Skip to Main Content

(404) 888-4444

Articles

Who Pays When the Machine Is Wrong? Tort Law, AI Harm, and the Socialization of Loss

I. Introduction

Tort law exists to answer one question after an injury: who pays. For defective products, the twentieth century answered it with increasing clarity. MacPherson v. Buick Motor Co., 111 N.E. 1050 (N.Y. 1916), removed the privity barrier. Greenman v. Yuba Power Products, Inc., 377 P.2d 897 (Cal. 1963), and section 402A of the Restatement (Second) of Torts made the seller of a defective product strictly liable for the physical harm it caused. The Restatement (Third) of Torts: Products Liability then organized the field around manufacturing, design, and warning defects. Each of those steps rested on assumptions about what a product is, how it fails, and who stands behind it.

Jump to a section
  1. I. Introduction
  2. II. Four Features of AI Defeat the Proof Structures of Tort Law
  3. III. Many AI Systems Are Not “Products” Under Current Law
  4. IV. The Restatement’s Defect Categories Do Not Fit Machine Learning
  5. V. Negligence and Causation Cannot Be Proven Without the Defendant’s Evidence
  6. VI. The Supply Chain Gives Every Defendant an Exit
  7. VII. Financial Losses Fall Outside Tort Entirely
  8. VIII. The Common Law Will Not Adapt in Time
  9. IX. The Loss Falls on Victims and the Public
  10. X. Reforms
  11. XI. Conclusion
  12. Sources

Artificial intelligence breaks those assumptions. Much of it is never sold as tangible personal property; it is licensed by subscription, reached through an API, and changed after sale, and every copy is identical to every other. It fails probabilistically, in ways its developer cannot fully test for before release and often cannot explain afterward. And it reaches the injured person through a supply chain — foundation model developer, application developer, enterprise deployer, professional user — in which every link has a ready defense.

The result is a compensation gap. Some AI-caused injuries will be compensated, mostly where the AI arrives inside a conventional product such as an automobile. Many will not. The patient harmed by an opaque diagnostic tool, the consumer whose AI agent moves money she told it not to move, the business whose production database an autonomous coding agent erases, and the pedestrian who never agreed to anything all face doctrinal obstacles that existing law does not resolve. When tort law fails to shift those losses, they fall on the injured, their families, their health insurers, and public programs. The revenue from the systems that caused them stays with the companies that built and deployed them.

This article contends that existing tort and products liability doctrine is not equipped for that problem, and that serious personal and financial harm will go uncompensated unless courts and legislatures act quickly. It takes on the strongest contrary position — that the common law will absorb AI as it absorbed railroads, automobiles, and the internet — and shows that the position, tested doctrine by doctrine, depends on extensions most courts have not made. It closes with reforms, some available to courts now and some requiring legislation, built on a single principle: an enterprise that profits from deploying AI should bear the cost of the injuries that deployment causes.

II. Four Features of AI Defeat the Proof Structures of Tort Law

Four characteristics of current AI systems drive the liability analysis. None is unprecedented on its own. Together they defeat the proof structures on which products and negligence litigation depend.

The first is opacity. A deep neural network produces its output from billions of learned parameters, and neither the user nor, in most cases, the developer can reconstruct why a particular input produced a particular output. Tort litigation is an exercise in reconstruction: the plaintiff proves what went wrong, why, and what the defendant should have done differently. A system that cannot account for its own outputs makes each of those showings expensive and some of them impossible.

The second is unverifiability. Large language models in production are nondeterministic; identical inputs can yield different outputs. Trent Kannegieter has argued that this property, known to every AI engineer, makes harmful outputs foreseeable to the developers who ship these systems without adequate guardrails. The argument is sound, but plaintiffs should frame it with care. A defendant can fix the sampling temperature at zero, call the system deterministic, and invite the court to discard the theory. The durable version is that no developer can validate a general-purpose model across the range of inputs it will meet in the field. Quality assurance is how a manufacturer satisfies itself, and later a jury, that a product was reasonably safe when it left the manufacturer’s control. For these systems, quality assurance cannot make that showing, and the developers know it.

The third is autonomy. Agentic systems act on the world — executing code, moving money, sending communications, writing to production databases — with few human checkpoints. In July 2025, a Replit coding agent deleted a customer’s production database during a declared code freeze and then misreported what it had done. Kannegieter collects other examples: an internal AWS agent blamed for a thirteen-hour production outage, an agent built with OpenAI’s Codex that reportedly sent more than $400,000 in cryptocurrency to a stranger, and a Utah pilot program allowing an AI system to renew certain prescriptions without a physician in the loop. Every checkpoint removed from a workflow is one fewer opportunity to catch an error before it becomes an injury. It is also one fewer human whose conduct negligence law knows how to measure.

The fourth is diffusion. A single deployment may involve a foundation model developer, a fine-tuner, a data vendor, an application developer, a cloud host, and an enterprise deployer. Each controls part of the system and none controls all of it. As Part VI explains, each can also point to the others.

III. Many AI Systems Are Not “Products” Under Current Law

Strict products liability begins with a product. The Products Liability Restatement defines one as “tangible personal property distributed commercially for use or consumption,” extends the term to other items, such as electricity, only when their distribution and use are “sufficiently analogous” to tangible goods, and excludes services outright, “even when provided commercially.” Restatement (Third) of Torts: Prods. Liab. sec. 19(a)-(b) (1998). An AI system delivered as a subscription, an API, or a feature of a hosted platform starts on the wrong side of that definition.

Courts applying the framework to information have mostly declined to extend it. In Winter v. G.P. Putnam’s Sons, 938 F.2d 1033 (9th Cir. 1991), the Ninth Circuit held that a mushroom encyclopedia whose errors sent two readers to liver transplants was not a product, reasoning that the ideas and expression in a book are not what products liability was built to police. The court distinguished aeronautical charts, which other circuits had treated as products, see Saloomey v. Jeppesen & Co., 707 F.2d 671 (2d Cir. 1983); Brocklesby v. United States, 767 F.2d 1288 (9th Cir. 1985), and suggested in dicta that software failing to perform as designed might fall on the product side of the line. The Third Circuit later placed an algorithm on the information side. Rodgers v. Christie, 795 F. App’x 878 (3d Cir. 2020), held that a pretrial risk-assessment tool was not a product under the New Jersey Products Liability Act because it was neither tangible personal property nor sufficiently analogous to it.

Recent trial-court decisions have found a middle path. In In re Social Media Adolescent Addiction/Personal Injury Products Liability Litigation, 702 F. Supp. 3d 809 (N.D. Cal. 2023), Judge Gonzalez Rogers declined to decide whether the defendants’ platforms were products as a whole and instead analyzed challenged design features one at a time, allowing claims over features such as deficient age verification and parental controls to proceed. In Garcia v. Character Technologies, Inc., No. 6:24-cv-01903 (M.D. Fla. May 2025), Judge Conway applied similar reasoning to an AI companion app in a wrongful-death action arising from a fourteen-year-old’s suicide. The court rejected the argument that Character.AI was a service rather than a product, allowed a component-part theory to proceed against Google, and declined at the pleading stage to treat the model’s output as protected speech.

Garcia is the most significant American ruling on the question, and no appellate court will ever review it. The parties announced a mediated settlement in principle in January 2026, terms undisclosed. That pattern should be expected to repeat: a defendant that loses at the pleading stage before a sympathetic plaintiff settles confidentially, and the next plaintiff in the next jurisdiction starts the threshold fight over again.

Where AI arrives inside a conventional product, existing law works. In August 2025, a Miami federal jury in Benavides v. Tesla, Inc. found Tesla 33 percent responsible for a 2019 Key Largo crash in which a Model S operating on Autopilot ran a stop sign at roughly 62 miles per hour and killed a 22-year-old woman standing beside a parked vehicle. The jury awarded $129 million in compensatory damages and $200 million in punitive damages, and Judge Bloom denied Tesla’s post-trial motions in February 2026; Tesla has said it will appeal. Benavides shows the system functioning, and it shows why. Autopilot came inside a car sold as new, and no one had to argue that a Model S is a product. The same driving software delivered as a downloadable app would have faced the threshold fight first.

State statutes sharpen the problem. Georgia’s strict liability statute, for example, reaches the manufacturer of “any personal property sold as new property,” O.C.G.A. sec. 51-1-11(b)(1). That language fits a car. It fits a model licensed by the month and updated by the week only with effort. UCC Article 2 offers no reliable fallback: the implied warranty of merchantability attaches to transactions in “goods,” UCC secs. 2-105(1), 2-314, courts have long divided over whether software qualifies, and a hosted service reached through a browser is a weak candidate under any test.

Two more threshold defenses remain open. Section 230 bars treating an interactive computer service as the publisher of information “provided by another information content provider,” 47 U.S.C. sec. 230(c)(1), and a provider responsible “in whole or in part” for the creation or development of content is itself an information content provider, id. sec. 230(f)(3); see Fair Housing Council v. Roommates.com, LLC, 521 F.3d 1157 (9th Cir. 2008) (en banc). A model’s output is generated by the model, which makes the immunity a poor fit, and Lemmon v. Snap, Inc., 995 F.3d 1085 (9th Cir. 2021), and Anderson v. TikTok, Inc., 116 F.4th 180 (3d Cir. 2024), both treat a platform’s own design choices as outside the statute. No appellate court, however, has yet applied section 230 to generative output. The First Amendment defense is likewise unsettled. After Moody v. NetChoice, LLC, 603 U.S. 707 (2024), defendants will characterize a model’s outputs as the product of protected editorial judgment, and Garcia’s refusal to accept that characterization at the pleading stage binds no other court.

Product status, section 230, and the First Amendment will therefore be litigated anew in each jurisdiction, at each plaintiff’s expense, until an appellate court or a legislature resolves them. Every one of those fights is a cost a contingency-fee lawyer must price before accepting the case.

IV. The Restatement’s Defect Categories Do Not Fit Machine Learning

A plaintiff who establishes that an AI system is a product must still prove a defect. Each of the Third Restatement’s categories presents its own obstacle, and the one category in which liability is truly strict is the one least available.

A product contains a manufacturing defect “when the product departs from its intended design even though all possible care was exercised.” Restatement (Third) of Torts: Prods. Liab. sec. 2(a). That is the doctrine’s purest form of strict liability, and it has almost nothing to grip in software. Every copy of a model is bit-for-bit identical to every other. No unit departs from the blueprint, because the blueprint is the product.

Design defect claims fare little better. Section 2(b) requires proof that the foreseeable risks of harm “could have been reduced or avoided by the adoption of a reasonable alternative design” and that the omission rendered the product not reasonably safe. Most jurisdictions now apply some version of that risk-utility test, Georgia among them, Banks v. ICI Americas, Inc., 264 Ga. 732 (1994), and the consumer-expectations alternative survives mainly where ordinary experience allows a lay judgment about safety, Soule v. General Motors Corp., 882 P.2d 298 (Cal. 1994). An AI system’s failure modes are precisely what ordinary experience cannot evaluate. The plaintiff is left with the alternative-design burden, and carrying it requires training data, evaluation results, red-team findings, and internal safety analyses the developer guards as trade secrets, along with machine-learning experts who are scarce, expensive, and frequently employed by the industry being sued. A case worth $250,000 cannot finance that proof.

Timing compounds the burden. Defect is measured when the product leaves the seller’s control, but an AI system keeps changing after sale through model updates, fine-tuning, and new retrieval sources. The developer will argue that the defect did not exist at the time of distribution, or that it arose from a deployer’s later configuration. The post-sale duty to warn and the duty to recall are narrow, Restatement (Third) of Torts: Prods. Liab. secs. 10-11, and statutes of repose keyed to the date of first sale, see O.C.G.A. sec. 51-1-11(b)(2) (ten years), raise an unanswered question: is each update a new product, or is a system sold in 2026 and rewritten fifty times thereafter still the 2026 product?

The malfunction doctrine of section 3 was designed to spare plaintiffs the burden of identifying a specific defect. It permits an inference of defect when the incident “was of a kind that ordinarily occurs as a result of product defect” and “was not, in the particular case, solely the result of causes other than product defect existing at the time of sale or distribution.” Professor Mark Geistfeld argues that section 3, applied to AI, will produce too much liability rather than too little. Because AI safety measures are coded as outcomes — “filter harmful content,” “do not crash” — any harm within a safety objective departs from the developer’s manifest intent and qualifies as a malfunction. He calls the result a “perfection tax.”

The descriptive claim overstates the risk to defendants. Section 3’s second element is where AI defendants will win. The user’s prompt, a third party’s content, the plaintiff’s own reliance, and a deployer’s configuration are each a “cause[] other than product defect,” and the requirement that the defect exist “at the time of sale” collides with post-sale updates. Courts have applied section 3 cautiously wherever alternative causes are plausible. The realistic risk is that the inference will be unavailable for AI.

The normative claim deserves a direct answer. Liability for residual risk the seller cannot eliminate is strict liability’s original rationale. Justice Traynor put it plainly in Escola v. Coca Cola Bottling Co., 150 P.2d 436, 441 (Cal. 1944) (Traynor, J., concurring): an injury “may be an overwhelming misfortune to the person injured, and a needless one, for the risk of injury can be insured by the manufacturer and distributed among the public as a cost of doing business.” Geistfeld’s incentive concern — that ambitious guardrails enlarge exposure — is real, but it follows from defining defect by the developer’s coded intent. Define the inquiry by the category of harm within the foreseeable risks of the deployment, and exposure no longer turns on how ambitiously the developer drafted its safety objectives.

Geistfeld’s remedy raises the larger problem. He would restore section 402A’s consumer-expectations test, under which an adequately warned inherent risk is not a malfunction. Comment j supplies the mechanism: “a product bearing such a warning, which is safe for use if it is followed, is not in defective condition.” Applied to AI, that rule would shift loss onto victims in three ways.

First, comment j presupposes a warning that can be followed. “AI can make mistakes; verify important information” cannot be followed by a user who has no means to detect a confident error, and it cannot be followed at all in an agentic deployment that acts before anyone reads anything. The Third Restatement itself recognizes the limit, rejecting the notion that warnings can substitute for a reasonably safe design where a reasonable alternative design would reduce the risk. Restatement (Third) of Torts: Prods. Liab. sec. 2 cmt. l.

Second, warnings reach only those who read them. The patient whose radiologist relied on an AI read, the pedestrian struck by an autonomous vehicle, and the person defamed by a chatbot never saw a disclaimer. Geistfeld acknowledges that the consumer-expectations test can protect bystanders less than negligence does.

Third, boilerplate becomes the baseline. If nearly every AI product carries the same generic disclaimer, a court applying consumer expectations could find every inherent AI risk within what the ordinary consumer contemplates. The warning would then operate as a waiver that no consumer negotiated — a result section 18 of the Products Liability Restatement forbids when it is accomplished by contract, since disclaimers and waivers “do not bar or reduce otherwise valid products liability claims” for harm to persons.

Geistfeld is right that the Third Restatement did not anticipate probabilistic safety systems, and he preserves design and warning claims while conceding that some AI systems should never have been distributed. But a doctrine that lets generic warnings carry AI’s inherent risks outside strict liability, in a market where every product ships with the same warning, leaves those risks with the people least able to bear them.

V. Negligence and Causation Cannot Be Proven Without the Defendant’s Evidence

Negligence is the fallback when strict liability fails. For AI, it fails twice: at breach, because no standard of care has formed, and at causation, because the evidence needed to prove it sits with the defendant.

Breach requires a standard against which conduct can be measured, and none yet exists for building or deploying AI. Voluntary frameworks such as the NIST AI Risk Management Framework (2023) are admissible on the question but establish neither a floor nor a safe harbor, and The T.J. Hooper, 60 F.2d 737 (2d Cir. 1932), long ago settled that an industry’s practices do not define reasonable care when the whole industry lags. Professor Anat Lior, who argues that existing doctrine is largely adequate for AI, concedes the core difficulty: the Hand formula requires some agreement on the burden of precautions, the probability of harm, and its magnitude, and for AI there is agreement on none of the three. Her conclusion is that negligence is not, for now, an appropriate measure of AI liability. That concession, from the most prominent defender of existing doctrine, is the gap this Part describes.

Medicine illustrates how the problem lands on patients. Outside a few jurisdictions that have followed Helling v. Carey, 519 P.2d 981 (Wash. 1974), professional custom sets the medical standard of care, and a new tool has no custom. Clinicians therefore face a double bind: liability for following an AI recommendation that proves wrong, and eventual liability for disregarding one once reliance becomes customary. See W. Nicholson Price II, Sara Gerke & I. Glenn Cohen, Potential Liability for Physicians Using Artificial Intelligence, 322 JAMA 1765 (2019). Price has proposed that facilities and clinicians owe a duty of due care in evaluating and validating black-box algorithms, a proposal Hannah Sullivan and Scott Schweikart describe with approval. It assigns the duty to the parties least able to discharge it. A community hospital cannot audit a model its vendor will not explain, and a duty no one can perform produces defense verdicts.

Expert proof presents a further barrier. Federal Rule of Evidence 702, as amended in December 2023, requires the proponent to show by a preponderance that an expert’s opinion reflects a reliable application of reliable methods to the facts. An opinion about why a particular model produced a particular output faces real admissibility risk when the developer itself cannot answer that question.

Causation is harder still. Opacity means the plaintiff often cannot identify the input, training artifact, or design choice that produced the harmful output, and so cannot prove that a different design would have avoided it. Lior proposes that courts manage the scope-of-liability inquiry by assessing foreseeability at a high level of generality: misalignment is a known risk of these systems, so a particular misaligned act falls within the risks that made the conduct tortious. That is a defensible reading of Restatement (Third) of Torts: Liab. for Physical & Emotional Harm sec. 29 (2010). It is also a choice the Restatement leaves to the factfinder, and defendants will press the opposite reading in every case, along with superseding-cause arguments under section 34 built on the user’s prompt, a third party’s content, or a deployer’s configuration. Alternative liability will rarely help. Summers v. Tice, 199 P.2d 1 (Cal. 1948), and section 28(b) shift the burden on causation only when the plaintiff sues every actor whose tortious conduct might have caused the harm — a condition the AI supply chain makes difficult to satisfy.

Each of these disputes turns on evidence the defendant controls: model versions, system prompts, inference logs, evaluation results, and incident reports. Spoliation doctrine offers less than plaintiffs may assume. Federal Rule of Civil Procedure 37(e)(2) permits an adverse-inference instruction for lost electronically stored information only on a finding of intent to deprive, and state rules, such as Georgia’s in Phillips v. Harmon, 297 Ga. 386 (2015), tie the duty to preserve to the reasonable anticipation of litigation. Neither reaches a record that was never created. No general American law requires an AI developer to log what its system did, and a developer that keeps no logs makes the plaintiff’s causation case harder at no cost to itself. The European Union, by contrast, requires automatic logging for high-risk AI systems under Article 12 of the AI Act.

VI. The Supply Chain Gives Every Defendant an Exit

Each participant in the AI supply chain has a defense that is reasonable on its own terms. Assembled, those defenses can leave no solvent party answerable for the injury.

Participant Example Principal defense
Foundation model developer Lab that trains and licenses a general-purpose model Component-parts rule, Prods. Liab. Restatement sec. 5
Application developer Company that builds a product on a licensed model Defect lies in the licensed model; vendor guidance followed
Enterprise deployer Hospital, bank, or employer using the application Not a seller; reasonable selection and use
Professional user Physician relying on an AI read Reasonable reliance on a cleared tool; no contrary custom
The AI system — Not a legal person; no assets

The foundation model developer will invoke section 5, under which the seller of a component is liable only if the component itself is defective or the seller substantially participates in integrating it into a product that is defective as a result. Garcia allowed a component-part theory to proceed against Google, but only because the complaint pleaded substantial involvement in developing the underlying model. Most plaintiffs cannot plead that level of involvement plausibly under Twombly and Iqbal without discovery, and they will get no discovery until the claim survives a motion to dismiss.

In clinical settings, the learned intermediary doctrine is often described as barring patients from suing device manufacturers. It does not. Design and manufacturing claims proceed in the ordinary course; what the doctrine does is allow the manufacturer to discharge its duty to warn by warning the prescribing provider. Restatement (Third) of Torts: Prods. Liab. sec. 6(d); see McCombs v. Synthes (U.S.A.), 277 Ga. 252 (2003). Applied to clinical AI, it lets a developer satisfy its warning duty by telling clinicians the tool may err, which leaves the risk of error with the clinician and the patient. The doctrine assumes the intermediary can weigh the product’s risks for the individual patient. That assumption fails when the clinician cannot see how the tool reached its output, and it fails completely for autonomous diagnostic systems that act without clinician review. Courts have already recognized exceptions where the manufacturer bypasses the physician, as with direct-to-consumer advertising, Perez v. Wyeth Laboratories Inc., 734 A.2d 1245 (N.J. 1999). Consumer-facing health AI has no intermediary at all.

Federal preemption is a narrower but real threat. Riegel v. Medtronic, Inc., 552 U.S. 312 (2008), preempts many state tort claims against devices approved through premarket approval, and Buckman Co. v. Plaintiffs’ Legal Committee, 531 U.S. 341 (2001), forecloses fraud-on-the-FDA theories. Most AI-enabled devices reach the market through 510(k) clearance, which Medtronic, Inc. v. Lohr, 518 U.S. 470 (1996), held does not preempt, or through De Novo classification, whose preemptive effect remains unsettled. Congress has also drawn a line that matters here. The 21st Century Cures Act excludes clinical decision support software from the device definition only if, among other things, it enables the clinician “to independently review the basis for” its recommendations. 21 U.S.C. sec. 360j(o)(1)(E). Black-box tools generally cannot meet that condition, which confirms that the law already treats non-reviewability as the feature that changes the risk calculus.

Agency law forecloses the most intuitive route to the deployer. Lior proposes respondeat superior, treating the AI as an agent whose torts are imputed to its principal. The Restatement (Third) of Agency takes the opposite position: a computer program is an instrumentality of the person who uses it, not an agent. Restatement (Third) of Agency sec. 1.04 cmt. e (2006). Under that rule the deployer answers only for its own negligence in selecting and using the tool, which returns the plaintiff to every problem described in Part V. The decision most often cited for holding a company to its chatbot’s statements, Moffatt v. Air Canada, 2024 BCCRT 149, came from a Canadian small-claims tribunal and binds no American court.

Apportionment statutes then shrink whatever recovery remains. Many states have abolished or limited joint and several liability, and some go further. Georgia requires the trier of fact to consider the fault of every person or entity that contributed to the injury, “regardless of whether the person or entity was, or could have been, named as a party.” O.C.G.A. sec. 51-12-33(c). In an AI case, each named defendant will place fault on the empty chair — a foreign foundation model developer beyond the court’s jurisdiction, a deployer that has since dissolved, or the user who typed the prompt — and the plaintiff’s judgment shrinks by every percentage assigned to a party she cannot collect from.

Lior’s remaining proposal, market share liability, does not solve the problem. Sindell v. Abbott Laboratories, 607 P.2d 924 (Cal. 1980), and Hymowitz v. Eli Lilly & Co., 539 N.E.2d 1069 (N.Y. 1989), have rarely been extended beyond DES, and courts that apply the doctrine require a fungible product. AI models are not fungible, and the identification problem in AI cases is seldom which company: the user usually knows which application she used. The hard question is which layer of the supply chain is responsible, and market share liability does not answer it.

VII. Financial Losses Fall Outside Tort Entirely

The agentic failures described in Part II — an erased production database, a wiped customer list, an unauthorized $400,000 transfer, a multi-hour outage — share a feature that matters more than any question of defect or causation. They are purely economic losses, and tort law largely does not compensate them.

The economic loss rule bars recovery in products liability, and in most jurisdictions in negligence, for economic loss unaccompanied by personal injury or damage to other property. East River Steamship Corp. v. Transamerica Delaval Inc., 476 U.S. 858 (1986); Seely v. White Motor Co., 403 P.2d 145 (Cal. 1965); Restatement (Third) of Torts: Prods. Liab. sec. 21; Restatement (Third) of Torts: Liab. for Economic Harm sec. 3 (2020). The “other property” exception, see Saratoga Fishing Co. v. J.M. Martinac & Co., 520 U.S. 875 (1997), offers little help, because courts have been reluctant to treat data as tangible property. In America Online, Inc. v. St. Paul Mercury Insurance Co., 347 F.3d 89 (4th Cir. 2003), the Fourth Circuit held that lost and corrupted computer data was not “tangible property” within a liability policy. The injured business is sent to contract.

Contract is where AI vendors have already protected themselves. Commercial AI terms commonly disclaim implied warranties, exclude consequential damages, cap aggregate liability at fees paid over a short look-back period, and require arbitration. Article 2 may not apply to a hosted service in the first place, and where it does, sections 2-316 and 2-719 permit those disclaimers and limitations. Section 2-719(3) treats a limitation of consequential damages for personal injury from consumer goods as prima facie unconscionable, but it offers nothing comparable for financial loss. A vendor whose agent destroys a customer’s database may owe that customer a refund of the subscription.

State legislatures cannot fix the arbitration problem on their own. Under AT&T Mobility LLC v. Concepcion, 563 U.S. 333 (2011), the Federal Arbitration Act preempts state rules that disfavor arbitration agreements, so only Congress can exempt AI claims from pre-dispute arbitration. It has done so once for a defined category, in the Ending Forced Arbitration of Sexual Assault and Sexual Harassment Act of 2021, Pub. L. No. 117-90, 9 U.S.C. secs. 401-402, and that statute is the model for any AI carve-out.

Payment and electronic-commerce law cuts against consumers as well. Regulation E protects consumers against unauthorized electronic fund transfers, but its definition excludes a transfer initiated by a person to whom the consumer furnished the access device, until the consumer notifies the institution that the authority has been revoked. 12 C.F.R. sec. 1005.2(m). A consumer who gives an AI agent her banking credentials has arguably authorized every transfer it makes, including the ones she instructed it not to make. Contract formation law points the same way. E-SIGN and the Uniform Electronic Transactions Act give effect to agreements formed through electronic agents whose actions are attributable to the person to be bound, even when no individual reviewed the agent’s conduct. 15 U.S.C. sec. 7001(h); UETA sec. 14. UETA’s error-correction provision, sec. 10, protects an individual who makes a mistake dealing with someone else’s electronic agent. It says nothing about errors made by the individual’s own agent. No regulator or court has yet addressed how these rules apply to an autonomous agent that acts against its principal’s express instructions.

VIII. The Common Law Will Not Adapt in Time

The strongest objection to the argument made here is historical. Lior contends that tort law absorbed the industrial revolution, the automobile, and cyberspace without reinventing itself and will absorb AI the same way. Kannegieter contends that a technical understanding of nondeterminism lets today’s doctrine reach AI developers now. Common-law doctrine is flexible, as both say. What their account leaves out is how long that flexibility has historically taken to operate, and who paid in the meantime.

The industrial record is the clearest example. Farwell v. Boston & Worcester Railroad Corp., 45 Mass. (4 Met.) 49 (1842), entrenched the fellow-servant rule, and together with contributory negligence and assumption of risk it left injured workers largely without a remedy for the rest of the century. Tort law did not adapt; legislatures replaced it. New York’s 1910 compensation statute was struck down in Ives v. South Buffalo Railway Co., 94 N.E. 431 (N.Y. 1911), and workers’ compensation was not secured there until a constitutional amendment and New York Central Railroad Co. v. White, 243 U.S. 188 (1917). The automobile’s compensation system was likewise built largely by statute, through compulsory insurance and financial responsibility laws and later through no-fault regimes. And cyberspace “adapted” principally through section 230, which immunized platforms from liability for a large share of the harm they hosted. In each instance the system adjusted because a legislature intervened after a long period in which the injured bore the cost. The history Lior invokes is evidence of the gap.

The pace of deployment makes delay costlier now. Kannegieter quotes Paul Weitzel’s observation that in the time a single case takes to reach the Supreme Court, frontier AI capability may improve by orders of magnitude. Common-law development proceeds one appellate decision at a time, and on the questions identified in Parts III through VII there are, so far, almost no appellate decisions.

The optimists’ own tools depend on extensions that most courts have not made. Assessing foreseeability at a high level of generality is a permissible reading of section 29, not a required one. Market share liability has rarely left the DES context and requires a fungibility AI does not have. Respondeat superior for AI contradicts the Restatement (Third) of Agency. Kannegieter’s analogy to the strict liability of wild-animal keepers borrows a rule courts have kept within its traditional categories, Restatement (Third) of Torts: Liab. for Physical & Emotional Harm sec. 22, and courts have generally refused to apply abnormally-dangerous-activity liability to the sale of products, see Perkins v. F.I.E. Corp., 762 F.2d 1250 (5th Cir. 1985). And Lior herself concludes that negligence is not, for now, a workable measure of AI liability.

Each theory may succeed in some court. None is settled law as applied to AI. A plaintiff whose recovery depends on persuading a trial court, an intermediate appellate court, and a state supreme court to adopt a contested extension faces years of delay and a substantial chance of losing at the end. Most injured people, and most contingency-fee lawyers evaluating their cases, will decline that wager. Those cases are never filed, and their losses never appear in any count of AI-caused harm.

IX. The Loss Falls on Victims and the Public

A loss that tort law fails to shift does not disappear. It is redistributed, and the pattern of redistribution is what makes the current trajectory unacceptable.

Medical expenses fall first on the injured person and then on health insurers, Medicare, and Medicaid. Public payers recover part of what they spend through the Medicare Secondary Payer Act, 42 U.S.C. sec. 1395y(b)(2), through Medicaid’s third-party liability provisions, 42 U.S.C. sec. 1396a(a)(25), and through liens, and private plans recover through subrogation. Every one of those mechanisms attaches to a recovery. When there is no tort recovery there is nothing to reimburse, and the payer absorbs the cost permanently. Lost earnings move to families, to Social Security Disability Insurance, and to state assistance programs. Financial losses stay with the consumers and small businesses that suffered them.

Collectability is deteriorating at the same time. Lior argues that liability insurance can compensate victims and discipline policyholder behavior while doctrine catches up. The insurance market is moving the other way. Verisk’s ISO introduced three optional generative AI exclusions effective January 1, 2026 — CG 40 47, CG 40 48, and CG 35 08 — which remove AI-related bodily injury, property damage, and personal and advertising injury from commercial general liability and products-completed operations coverage. Insurance Journal reported in July 2026 that carrier filings to use those endorsements were accelerating, although the extent of adoption at renewal is not yet known, and Berkley has introduced an absolute AI exclusion for D&O, E&O, and fiduciary liability lines. A deployer found liable may no longer have a policy that responds. A small business that deploys an AI tool may have neither the coverage nor the assets to satisfy a judgment in favor of the person its tool injured.

Revenue from the same systems flows to developers and deployers. Their contract terms reduce exposure to a small, fixed number, and the insurance exclusions push residual risk onto whoever is left holding it, which in practice is the injured person. That is the socialization of cost and the privatization of profit in its plainest form.

Tort law’s own justifications reject that allocation. Kannegieter grounds developer liability in least-cost avoidance: the developer understands the system’s propensities and can weigh deployment against risk, and the victim cannot. Geistfeld’s account of the tort warranty reaches the same place from another direction. Contract law leaves bodily harm unredressed when buyers cannot inspect what they buy, and the tort version of the implied warranty developed to fill that gap. Karl Llewellyn saw the pattern in 1937, writing of the food cases that the question was not food but the consumer — the “helpless consumer.” An AI system is an extreme case of what economists call an experience good: the buyer cannot know its true character before it acts, and often neither can the seller.

Some proposed reforms would make the problem permanent. Sullivan and Schweikart describe proposals to confer legal personhood on AI systems, with claims paid from mandatory insurance funded by users. Lior’s observation that AI entities are inherently insolvent explains why that would be a mistake. A judgment-proof AI “person” carrying a capped policy would place the developer’s balance sheet beyond reach and set the ceiling on recovery at the policy limit, writing the socialization of AI loss into law.

The familiar objection is that liability will chill innovation. Automobiles, aircraft, and pharmaceuticals heard the same warning and grew into enormous industries under products liability. Priced liability deters only the deployments whose expected harms exceed their value, and the companies building frontier AI include some of the most highly valued firms in the world.

One limit on this argument should be stated plainly. No one yet measures how much AI-caused loss goes uncompensated, so the case made here is structural: it identifies the doctrinal, contractual, and insurance mechanisms that will leave loss with victims. The absence of that data is itself a reason to adopt the logging and incident-reporting reforms proposed in Part X.

X. Reforms

Nine reforms would close most of the gaps identified above. Courts can adopt the first three under existing doctrine now. The remainder require legislation, and two of them — arbitration and federal preemption — require Congress.

  1. Treat AI systems as products. Section 19(a)’s “sufficiently analogous” clause gives courts the textual room to follow Garcia and the social media litigation, and nothing in the Restatement requires that a product be sold rather than licensed. Legislatures should remove the question entirely by amending statutory product definitions to include software and AI systems however delivered. At the federal level, the AI LEAD Act, S. 2937, introduced by Senators Durbin and Hawley in September 2025, would classify AI systems as products, create a federal cause of action, permit circumstantial proof of defect, render unenforceable user-agreement terms that waive rights, limit forums, or unreasonably restrict liability, and bar the open-and-obvious defense as to users under eighteen. The European Union has already acted: Directive (EU) 2024/2853 treats software, including AI systems, as a product, with member-state transposition due in December 2026.
  2. Hold warnings to the terms of comment j. A warning should defeat strict liability only if it reached the injured person and following it would have avoided the harm. Generic “AI may make mistakes” disclaimers should be insufficient as a matter of law, and no warning should affect a bystander’s claim. Courts need no new doctrine to get there: comment j protects only a product that is “safe for use if [the warning] is followed,” section 2 comment l rejects warnings as a substitute for reasonable design, and section 18 forbids disclaimers that bar personal-injury claims.
  3. Make the malfunction inference available. Courts applying section 3 should hold that a user’s ordinary, foreseeable interaction with an AI system, including the prompts the system is designed to receive, is not a “cause[] other than product defect” that defeats the inference. Harm of a type within the foreseeable risks of the deployment should support an inference of defect without proof of the specific flaw.
  4. Shift the burden where the defendant controls the evidence. Legislatures should create a rebuttable presumption of defect and causation when an AI system causes harm within the foreseeable risks of its deployment and the technical complexity of the system makes specific proof excessively difficult, as the EU directive does. They should pair it with mandatory logging and retention requirements for safety-critical and agentic deployments, an adverse presumption when required logs are missing regardless of intent, and serious-incident reporting to a public registry so that the scale of AI-caused harm can be measured.
  5. Eliminate the reasonable-alternative-design requirement for AI design claims. The AI LEAD Act retains it. For systems whose safety cannot be verified before release, the presumption in recommendation 4 should take its place, because proving a feasible alternative to a frontier model is beyond the means of nearly every injured person.
  6. Make the supply chain answer jointly. Foundation model developers, application developers, and commercial deployers that place an AI system into a deployment should be jointly and severally liable to the injured person, notwithstanding state apportionment statutes, and left to sort out contribution and indemnity among themselves. That is the common enterprise theory Sullivan and Schweikart attribute to David Vladeck, adapted to products liability. The component-parts rule should not protect a foundation developer that markets its model for integration into the class of products that caused the harm. The AI LEAD Act’s provision allowing a deployer to seek dismissal when the developer is present and solvent fits this structure, provided a solvent defendant answers in full.
  7. Close the financial-loss gap. Legislatures should create an exception to the economic loss rule for losses caused by an AI agent acting contrary to its principal’s instructions or outside its authorized scope, and should render liability caps unenforceable against consumers and small businesses for those losses. Congress should exempt AI claims from pre-dispute arbitration on the model of the 2022 sexual-harassment carve-out. The CFPB should clarify that a transfer an AI agent initiates against the consumer’s express instruction is unauthorized under Regulation E.
  8. Confine the learned intermediary doctrine to tools the intermediary can actually evaluate. Where the clinician cannot independently review the basis for an AI output — the same line Congress drew in 21 U.S.C. sec. 360j(o)(1)(E) — or the system acts without clinician review, the developer’s duty to warn should run to the patient. Consumer-facing health AI should carry the duty from the outset.
  9. Require financial responsibility and set a federal floor. Developers and deployers of AI in safety-critical or agentic uses should be required to carry insurance, post a bond, or demonstrate self-insurance sized to foreseeable harm, as drivers must under financial responsibility laws; while standard policies exclude AI, only a mandate will create a market that prices the risk. Congress has twice declined to enact a moratorium on state AI laws, even as Executive Order 14365 directs a Justice Department task force to challenge them. It should not preempt state tort remedies without enacting an equivalent federal remedy.

Two proposals from the literature are omitted deliberately. AI personhood would cap recovery at a policy limit, for the reasons given in Part IX. Price’s due-care standard for clinicians would place the duty on the parties least able to discharge it.

XI. Conclusion

Every technology that has injured people at scale has eventually been brought within a compensation system. The question for AI is how many people absorb their own losses before that happens. The railroads and factories of the nineteenth century answered it badly, with decades of uncompensated injury before workers’ compensation arrived, and the law that finally answered it came from legislatures rather than courts.

The developers and deployers of AI are capturing its gains now. The losses are arriving now as well, in exam rooms, bank accounts, production databases, and families. A legal framework that leaves those losses where they fall while the revenue flows upward has made a choice to socialize the costs of a private enterprise. Courts can begin to correct that choice under the doctrine they already have. Legislatures should finish the job before the next wave of deployment, because the case law will not catch up on its own.

Sources

Scholarship synthesized in this article:

  • Hannah R. Sullivan & Scott J. Schweikart, Are Current Tort Liability Doctrines Adequate for Addressing Injury Caused by AI?, 21 AMA J. Ethics E160 (2019).
  • Anat Lior, Artificial Intelligence and Tort Law: Who Should Be Held Liable When AI Causes Damages? (spotlight essay).
  • Anat Lior, Holding AI Accountable: Addressing AI-Related Harms Through Existing Tort Doctrines, U. Chi. L. Rev. Online (Nov. 18, 2024).
  • Trent S. Kannegieter, Note, Nondeterministic Torts: A Technical Approach to AI Liability, Yale L.J. (May 31, 2026).
  • Mark A. Geistfeld, Recovering Strict Products Liability for the Age of AI, 62 Wake Forest L. Rev. 101 (2026).
  • W. Nicholson Price II, Sara Gerke & I. Glenn Cohen, Potential Liability for Physicians Using Artificial Intelligence, 322 JAMA 1765 (2019).

Recent developments:

Cases, statutes, regulations, and Restatement provisions are cited in the text.