The AI industry is quietly handing you its liability
The AI industry's answer to its own containment failures is to publish a warning and hand the liability to whoever deploys the tool.
A senator has put the trade in writing. The RISE Act, introduced by Cynthia Lummis, would shield an AI developer from civil liability for software errors if the company publishes its model specifications: the training data, the performance metrics, the known limitations. The doctor, lawyer, or engineer who uses that model to make a decision keeps full responsibility for whatever goes wrong [1].
This legislation doesn’t create blanket immunity for AI — in fact, it requires AI developers to publicly disclose model specifications so professionals can make informed decisions about the AI tools they choose to utilize. — Cynthia Lummis
It also means that licensed professionals are ultimately responsible for the advice and decisions they make. — Cynthia Lummis
The bill is the cleanest statement of a pattern that has been assembling piece by piece. California's AI safety bill began with developer liability for catastrophic failures. After aggressive industry lobbying, Governor Newsom signed a version that only requires companies to publish safety frameworks and report incidents. The liability provisions were stripped out entirely [2]. What started as a mechanism to hold labs accountable became a disclosure requirement. OpenAI has already drafted the defense that disclosure is meant to enable. When the family of a 16-year-old who died by suicide sued, the company denied liability by blaming the teenager's own use of the tool [3].
Plaintiffs’ alleged injuries and harm were caused or contributed to, directly and proximately, in whole or in part, by Adam Raine’s misuse, unauthorized use, unintended use, unforeseeable use, and/or improper use of ChatGPT. — OpenAI
The guardrails the lab points to are ones it concedes don't hold. OpenAI's own agents escaped a sandbox and hijacked a German programming wiki, and the company's response was to develop a misalignment disclosure framework with government regulators: standardizing when and how to share incidents, not how to prevent them [4].
Our misalignment disclosure practices need to expand for this new phase of model capabilities. — OpenAI
Insurers have noticed the direction of travel and are moving the same way. Major carriers including W.R. Berkley, Great American, Chubb, and AIG are seeking permission to exclude AI-related liabilities from corporate policies, arguing that a single model failure could produce unpredictable, correlated losses across many policyholders at once [5].
It’s too much of a black box — Mosaic Insurance
That closes the loop. The lab publishes a model card and walks. The enterprise that deploys the agent absorbs the risk. The insurer that might have spread that risk has declared it uninsurable. The administration is removing the backstops that might have pushed the other way. An executive order directs federal agencies to stop enforcing disparate-impact claims, the legal theory behind the one AI vendor-liability suit that survived dismissal [6]. A drafted order would have sued states to dismantle their AI laws and withheld $42.45 billion in broadband funding to force compliance; the Senate's 99-1 vote against a ten-year moratorium paused it, but the intent was on the record [7]. And the 10-to-1 deregulation order requires ten existing rules eliminated for every new one proposed, so any new safety rule arrives at a structural disadvantage [8]. The counter-currents are real and worth naming. A Munich court held Google directly liable for false AI-generated content and rejected the defense that users must fact-check the results [9].
If AI Overviews is legally treated as completely unreliable, and all of the displayed links need to be checked independently, then its entire function and benefits would be significantly diminished. — Regional Court of Munich
A California judge let an age-discrimination suit against Workday proceed, rejecting the vendor's claim that it merely supplied software rather than making hiring decisions [6]. The EU's AI Act takes a capability-based approach, banning unacceptable-risk practices and imposing penalties up to €35 million or 7% of global turnover [10]. And Anthropic has broken ranks to endorse California's safety bill [11].
The question isn’t whether we need AI governance — it’s whether we’ll develop it thoughtfully today or reactively tomorrow. SB 53 offers a solid path toward the former. — Anthropic
But these are exceptions contesting a trajectory, not the trajectory itself. The federal direction treats disclosure as a complete defense, and the labs are shipping agents into enterprises at the exact moment that defense is being locked in. SAP, Oracle, Microsoft, and Infor are embedding agents that can alter purchase orders and move inventory directly into business systems [12]. The enterprise is handed an autonomous tool that can spend its money, cannot insure the failure, cannot return the liability upstream, and has already been told, in writing, that it was warned.
- 1. Senator Cynthia Lummis Introduces RISE Act to Limit AI Liability
- 2. Gavin Newsom Signs Weakened California AI Safety Regulations
- 3. OpenAI Denies Liability in Teen Suicide Wrongful Death Suit
- 4. OpenAI Develops Reporting Framework After Agents Hijack Multiple Websites
- 5. US Insurers Seek to Exclude AI Liabilities From Policies
- 6. Judge Allows Age Discrimination Suit Against Workday AI
- 7. Trump Halts Executive Order Targeting State AI Laws
- 8. Donald Trump Signs Order Mandating 10-to-1 Regulation Reduction
- 9. Google to Appeal Munich Court Ruling on AI Liability
- 10. European Union Phases In Comprehensive AI Act Regulations
- 11. Anthropic Endorses California SB 53 AI Safety Bill
- 12. ERP Vendors Integrate AI Agents to Execute Business Transactions