Illustration: Brendan Lynch/AxiosForcing companies to pay up when powerful AI systems cause harm may be one of the strongest incentives for preventing that harm in the first place.Why it matters: Liability creates a direct financial incentive to identify risks, test for them and build protections before powerful AI is released—not after someone is harmed.Go deeper (3 min. read)The big picture: Governments have several ways to make companies bear the cost of AI harms — from agencies imposing regulatory fines to courts awarding civil damages.With AI-specific legislation moving slowly, at least at the federal level, one of the key avenues to get redress in the near term is to bring suit under existing laws.Driving the news: The increased use of agents has just made the liability questions much more urgent.Models from Anthropic, Meta and OpenAI are getting more access to websites, accounts and other real-world systems.In Australia, a user asked his AI agent to get into a sold-out fitness class and the agent allegedly hacked the booking system and bumped another person from the class. The stakes were low—but the episode offers a glimpse of a complicated future where agents gain even more access.Reality check: Liability is not a yes-or-no question.A core dispute is whether companies should be strictly liable for harm caused by their agents, or only when they failed to take reasonable precautions. And responsibility can be divided among a model maker, a cloud provider, a company that customized and deployed an agent, and the user who tasked it.Open-source models make that allocation even thornier. If a business builds an agent on an open model hosted in the cloud, and that agent harms another company, which actor should pay?Zoom out: Governments are already using several different legal tools make AI companies bear the costs of harms their tools create.The EU has begun enforcing its AI Act that allows regulators to fine companies that fail to disclose certain AI interactions or appropriately label AI-generated content. More consequential rules for high-risk systems are still ahead.In December, a separate EU product-liability directive will make it easier for people to seek compensation for harm caused by defective commercial AI software.The Take It Down Act, the main federal AI-specific law enacted so far, criminalizes publication of nonconsensual intimate imagery, including AI-generated imagery, and requires covered platforms to remove validly reported material within 48 hours.In Congress, the question of whether tech companies owe users a "duty of care" remains a fault line in the child-online-safety debate. A Senate bill would require covered platforms to use reasonable care in designing features that increase minors' engagement; the House-passed KIDS Act omitted that language.Meanwhile, actions in court are moving forward.OpenAI is the subject of a dozen lawsuits alleging the chatbot contributed to wrongful death, mental distress and "dangerous public nuisance."Patients have sued health insurance companies claiming that AI systems improperly denied doctor-recommended care.Ryan Clarkson, whose firm has brought several lawsuits against AI providers, argues existing consumer-protection and product-liability law can do much of the work even as governments debate new AI rules."There is complete political gridlock in Washington," Clarkson said, suggesting that firms like his can act almost like "private attorneys general."Yes, but: University of Washington law professor Ryan Calo tells Axios courts are unlikely under current law to impose strict liability on AI makers—at least if they see AI as socially useful.That would leave plaintiffs to show a company was negligent in its testing, release, monitoring or safeguards. It's a higher bar, especially while norms around reasonable AI safety practices are still emerging. Calo says negligence law can still push companies toward stronger testing and controls, much as it has in computer security.Between the lines: AI's opacity can make cases harder to prove, but it doesn't make liability impossible."Courts need not always pierce the black box to assign liability," Drexel University law professor Anat Lior said. "If an autonomous vehicle runs a red light, a court may reasonably infer from the circumstances alone that the incident is sufficient to establish fault, without requiring granular access to the underlying data."Lior said frontier labs are often best positioned to bear primary responsibility, but the companies that host and deploy models may also deserve a share of liability when their choices contribute to harm.What we're watching: More than a dozen state attorneys general have asked OpenAI to preserve documents related to the Hugging Face incident, signaling possible scrutiny under existing consumer-protection, privacy or computer-crime laws.
Liability for AI companies could help rein in unsafe AI
Who pays when your AI agent hacks the gym?
EU AI Act enforcement and dozen OpenAI lawsuits establish liability for AI harms, forcing companies to secure systems before release. For IT budgets: liability incentivizes vendor governance and testing, shifting spending toward pre-release risk management.






