When an artificial intelligence system causes harm, AI liability generally falls on the party that had the most control over the behavior that caused the injury: the developer who built and trained the model, the company that deployed it, or in some cases the end-user who fed it bad inputs or ignored its warnings. There is no single federal AI liability statute in the United States. Instead, courts apply existing frameworks — products liability, negligence, anti-discrimination law, and consumer protection statutes — to figure out who pays.
How Courts Decide Who Is Responsible
Tort law does most of the work, through two main theories.
Negligence asks whether a developer, manufacturer, or operator failed to exercise reasonable care when building or deploying the system. A court compares the defendant’s conduct to what a reasonably careful company in the same position would have done. The hard part is the “black box” problem: if nobody can explain why an algorithm reached a particular decision, proving carelessness requires forensic work on the model’s architecture, training data, and decision weights.
Strict liability changes the analysis. When a court treats an AI system as a product rather than a service, the injured person does not have to prove anyone was careless. The question is whether the product was defective. That classification matters because many AI systems sit uneasily between the two categories. Where the system counts as a product, a plaintiff can bring three kinds of defect claims:
- A design defect claim argues the AI’s architecture was inherently dangerous for its intended use.
- A manufacturing defect claim targets errors introduced during development or training that caused the system to deviate from its intended design.
- A failure-to-warn claim argues the company did not disclose known limitations or foreseeable risks.
Design defect claims are often evaluated under a risk-utility test that weighs the technology’s benefits against its inherent dangers. If a safer alternative design was feasible and economically practical at the time of production, the manufacturer’s exposure grows. Damages typically cover medical expenses, lost income, and property damage.
Which Party Actually Pays
Assigning fault means tracing the system’s lifecycle from initial code to final deployment. Developers who write the core algorithms and train the neural networks face upstream liability when foundational flaws in their code propagate into multiple products. Hardware manufacturers who embed that software into physical devices — robotic surgical arms, vehicle sensors — share responsibility for how their equipment responds to software commands.
Downstream liability lands on the businesses and individuals who deploy the AI in daily operations. An end-user who feeds biased or incomplete training data into an otherwise well-designed algorithm may bear responsibility for the discriminatory or harmful outcomes that result. The same applies when someone uses a system outside its intended purpose or modifies it without the developer’s knowledge. Courts have to distinguish a flaw built into the tool from misuse of a working tool.
When more than one party contributed to the harm, courts apply comparative fault. Financial responsibility is split according to each party’s degree of control over what happened. A jury might assign 50 percent of the fault to the developer for a training data flaw, 30 percent to the deploying company for inadequate oversight, and 20 percent to the end-user for ignoring safety warnings. Working out those percentages requires close reading of licensing agreements, service-level contracts, and technical documentation showing who controlled what at each stage.
AI Liability in Autonomous Vehicles
Self-driving cars offer the clearest real-world test of these doctrines, because software failures translate directly into collisions, injuries, and deaths. NHTSA oversees automated vehicle safety at the federal level and requires manufacturers to certify compliance with Federal Motor Vehicle Safety Standards.1NHTSA. Automated Vehicle Safety Testing occurs in limited, designated locations under state permits, with NHTSA monitoring safety performance through a Standing General Order mandating crash reporting.
The financial consequences of noncompliance are steep. Federal regulations set civil penalties at up to $27,874 per violation, and each vehicle counts as a separate violation. For a related series of violations, the maximum penalty reaches nearly $139.4 million.2eCFR. 49 CFR Part 578 – Civil and Criminal Penalties Private lawsuits can far exceed those figures. A Florida jury held Tesla partially responsible for a fatal crash involving its Autopilot system and awarded $243 million in damages, despite Tesla’s warnings that the driver had to remain attentive.
Liability allocation in autonomous vehicle crashes depends on the level of automation. When the system requires a human driver to stay alert and ready to intervene, courts look closely at who bore primary responsibility at the moment of impact. As vehicles approach full autonomy with no human input expected, the liability burden shifts almost entirely to the manufacturer, because no human operator remains to blame.
AI Liability in Healthcare
Hospitals now use AI diagnostic tools and clinical decision-support systems routinely, and liability here reflects a core medical principle: the physician remains responsible for the patient. Malpractice law requires doctors to exercise independent professional judgment. A physician who follows an AI-generated recommendation that harms a patient will typically face liability first, especially if contradictory clinical evidence was available and ignored. The algorithm is one input, not a substitute for the doctor’s training.
Software companies are not off the hook. When a medical software product causes providers to order medically unnecessary procedures, the consequences reach the developer. In one federal case, a software company agreed to pay over $529,000 to resolve allegations that a flaw in its risk-calculation tool led to unnecessary breast cancer screenings billed to Medicare.3United States Department of Justice. Medical Software Company Agrees to Pay $500,000 to Resolve Allegations of Causing Medically Unnecessary Breast Cancer Screening Claims Hospitals and clinics also face institutional liability when they deploy AI tools without adequately training staff on the system’s limitations, fail to validate outputs against clinical standards, or skip required oversight. Liability in healthcare stacks: software company, institution, and individual physician can all be on the hook at the same time.
AI Liability in Hiring
Federal anti-discrimination law applies to AI hiring and employment tools with the same force it applies to human decision-makers. Title VII of the Civil Rights Act prohibits employment practices that cause disparate impact based on race, color, religion, sex, or national origin, unless the employer can show the practice is job-related and consistent with business necessity.4Office of the Law Revision Counsel. 42 USC 2000e-2 – Unlawful Employment Practices An AI resume screener that systematically filters out candidates from a protected group triggers the same analysis a human recruiter would face for doing the same thing. Even where the discrimination is unintentional and baked into training data, the employer is liable.
The EEOC has said employment discrimination laws apply to AI and other new technologies “just as they apply to other employment practices.”5U.S. Equal Employment Opportunity Commission. What Is the EEOCs Role in AI Employers cannot shift blame to a third-party vendor that built the tool. If you buy an AI screening product and it discriminates, your organization carries the legal exposure. The vendor may owe you indemnification under your contract, but the workers harmed will look to the employer.
AI Liability in Lending and Credit Decisions
Lenders using AI or machine-learning models for credit decisions must comply with the Equal Credit Opportunity Act, which prohibits discrimination on the basis of race, color, religion, national origin, sex, marital status, or age in any aspect of a credit transaction.6Office of the Law Revision Counsel. 15 USC 1691 – Scope of Prohibition A model that produces discriminatory lending outcomes can expose the creditor to disparate impact liability even if the model was never designed to consider protected characteristics. If a less discriminatory alternative could serve the same business purpose, the lender’s failure to adopt it strengthens the plaintiff’s case.
Explaining AI-driven denials is a separate compliance problem. Under Regulation B, when a creditor takes adverse action against an applicant, it must give the applicant a written notice stating the specific reasons for the decision.7eCFR. 12 CFR 1002.9 – Notifications Vague explanations like “credit history” or “purchasing patterns” do not satisfy the rule. The CFPB has said there is no AI exemption from these notice requirements: creditors must provide specific, accurate reasons for denial even when using complex algorithms, and cannot hide behind a black-box model.8Consumer Financial Protection Bureau. CFPB Issues Guidance on Credit Denials by Lenders Using Artificial Intelligence If the model cannot produce reasons a human applicant would understand, the lender is in violation.
Liability for AI-Generated Content
Who is responsible when a generative AI model produces harmful output is one of the most unsettled questions in the field. Section 230 of the Communications Decency Act says no provider of an interactive computer service can be treated as the publisher or speaker of information provided by “another information content provider.”9Office of the Law Revision Counsel. 47 USC 230 – Protection for Private Blocking and Screening of Offensive Material Whether that shield covers content an AI model itself generates is a question courts have not definitively answered. A Congressional Research Service analysis frames the issue on a spectrum: the more the AI functions like a search engine retrieving existing content, the more plausible Section 230 protection becomes; the more it functions as a creative engine generating novel content, the less likely protection is.10Congress.gov. Section 230 Immunity and Generative Artificial Intelligence
Defamation from Hallucinations
AI hallucinations — false statements a model generates about real people — have already produced defamation lawsuits. In Walters v. OpenAI, a court granted summary judgment to OpenAI, finding a reasonable reader would not treat ChatGPT output as a factual assertion about the plaintiff and that the plaintiff had not shown damages or actual malice. That ruling turned on its specific facts and does not create a blanket rule protecting AI companies from all hallucination claims. A plaintiff who can show real reputational damage, wider publication, and a more clearly defamatory statement will present a much harder case to dismiss.
Copyright Infringement
When AI output closely mirrors copyrighted material from the training data, the copyright owner can sue for infringement. Statutory damages range from $750 to $30,000 per work, and if the infringement is found to be willful the court can increase the award to $150,000 per work.11Office of the Law Revision Counsel. 17 USC 504 – Remedies for Infringement: Damages and Profits Who pays depends on who prompted the output and how it was used. A developer whose model routinely reproduces protected material faces different exposure than an end-user who unknowingly publishes an infringing image.
Federal and State Enforcement
Several federal agencies have said plainly that they will hold companies accountable for AI-related harms under existing authority, without waiting for Congress. The FTC has stated there is “no AI exemption from the laws on the books” and has gone after companies using AI to mislead consumers, including those making unsubstantiated claims about AI capabilities and those deploying AI tools that facilitate deceptive practices like fake reviews.12Federal Trade Commission. FTC Announces Crackdown on Deceptive AI Claims and Schemes Marketing an AI product as equivalent to a human professional invites enforcement if the claim cannot be backed with evidence.
States are moving too. Colorado enacted legislation requiring both developers and deployers of high-risk AI systems to use reasonable care to protect consumers from algorithmic discrimination, with violations treated as deceptive trade practices enforceable by the state attorney general. Other states and cities have introduced their own rules for automated employment decision tools, bias audits, and consumer notification.
Contracts, Disclaimers, and Insurance
Most AI companies try to manage their exposure through contracts long before a lawsuit is filed. Terms of service commonly cap total recoverable damages, often at the fees paid over the prior twelve months or a fixed dollar amount. Indemnification clauses frequently require the customer to cover the developer’s legal costs if the customer’s data, inputs, or misuse of the system caused the harm.
These contractual protections have limits. Courts can refuse to enforce limitation-of-liability clauses they find unconscionable, particularly when the clause is buried in a clickwrap agreement, bargaining power is grossly unequal, or the clause effectively eliminates the victim’s ability to recover anything. Consumer protection statutes in many jurisdictions also restrict how much liability a company can disclaim for certain categories of harm, especially personal injury. A clause that looks bulletproof in a negotiation room may not survive judicial scrutiny after someone is seriously hurt.
Insurance fills some of the remaining gap. Policies increasingly cover AI-specific risks including data breaches, professional errors caused by algorithmic failures, and defense costs in intellectual property disputes. Premiums vary based on industry, the level of autonomy the system exercises, and the company’s incident history. For companies deploying AI in high-stakes contexts like healthcare or lending, adequate coverage is no longer optional.