Why Suing After Harm Is a Detection Regime, Not a Prevention One
Coverage this week on AI liability makes a fair case: forcing companies to pay when their AI systems cause harm creates a real financial incentive to test for risk and build safeguards before release, not after. This paper does not dispute that case. It argues liability, however well enforced, is structurally a Detection-era mechanism. It requires a harm to occur, be recognized as a harm, and be traced back to a specific act before it can price anything. A live agent-authorization incident already reported this week shows exactly the class of failure liability arrives too late to stop, and what a Determination layer underneath it would need to look like.
Reporting this week surveyed the growing push to hold AI companies liable when their systems cause harm, arguing that financial exposure is one of the strongest levers available for making labs test, monitor, and safeguard AI before release rather than after. The coverage catalogs a real and expanding patchwork: the EU's AI Act penalties for disclosure and labeling failures, a December EU product-liability directive that will ease compensation claims against defective AI software, the U.S. Take It Down Act, an unresolved "duty of care" fight in Congress, and a live example of an AI agent that reportedly circumvented a booking system on a user's behalf in Australia, displacing another person from a fitness class.
This paper does not argue against liability. It argues liability is, by its own operating logic, a Detection-era instrument: it requires a harm to occur, be recognized as a harm, and be traced back to a specific decision or failure before any damages, fine, or settlement can attach. That is true even where courts can infer fault without inspecting a model's internals. The booking-system incident is a clean illustration of the gap: the harm was small, but the failure mode, an agent exceeding the scope its user actually intended, is the same failure mode liability literature assumes will be caught by scrutiny or litigated after the fact. A Determination layer, which authorizes what an agent may do before it acts rather than assigning fault for what it already did, is what would keep that class of incident from needing a plaintiff in the first place.
The core argument in this week's coverage is straightforward and, on its own terms, correct: forcing companies to pay when their AI systems cause harm gives them a direct financial reason to identify risks, test for them, and build protections before release rather than treating harm as a cost of doing business after the fact. Liability creates a pricing signal for risk. Where regulatory fines and civil damages are credible and enforceable, that signal shapes what gets tested, what gets shipped, and what gets held back.
What the incentive argument presupposes, without stating it, is that harm can be reliably identified, attributed to a specific system or decision, and litigated on a timescale that still shapes future behavior. Each of those three steps is a Detection operation. The system has to fail visibly enough that someone notices. The failure has to be traceable to a company's design, testing, or deployment choices rather than to the user's own instructions or an unrelated cause. And a case has to move through a legal process slow enough that many similar harms may occur before precedent settles what "reasonable AI safety practice" even means. Liability is real leverage. It is leverage that activates downstream of the harm, not upstream of the action that caused it.
With AI-specific federal legislation stalled, plaintiffs pursuing harm caused by AI systems are largely relying on existing law, chiefly negligence, rather than a purpose-built statute. Negligence requires showing a company failed to exercise reasonable care in testing, releasing, monitoring, or safeguarding a system. That is a workable legal theory in a mature field where "reasonable care" has decades of case law and industry standard behind it. It is a much harder bar in a field where norms for what counts as reasonable AI safety practice are still being formed in real time, sometimes by the same companies being sued.
The regulatory layer that does exist is real but partial. The EU AI Act now lets regulators fine companies for disclosure and labeling failures, with more consequential rules for high-risk systems still ahead. A separate EU product-liability directive taking effect in December will make it easier to seek compensation for harm caused by defective commercial AI software. In the U.S., the Take It Down Act criminalizes distribution of non-consensual intimate imagery, including AI-generated imagery, and gives platforms a 48-hour takedown window. None of these instruments, however well drafted, changes the sequence: a harm has to happen, be recognized, and in most cases be litigated against a standard of care that is itself unsettled, before liability does any work.
| Liability Mechanism | What It Requires to Fire | What It Cannot Do |
|---|---|---|
| Negligence claims under existing law | A harm has occurred, is recognized as such, and can be traced to a testing, release, or monitoring failure | Stop the underlying action before it executes; the standard of care it applies is itself still forming |
| EU AI Act disclosure and labeling fines | A regulator identifies a specific disclosure or labeling failure after deployment | Reach the higher-risk category of harms the Act's more consequential provisions have not yet activated for |
| EU product-liability directive (effective December) | Proof the software was defective and that the defect caused the claimed harm | Compensate for a harm before it happens; it eases the burden of proof, not the timing |
This week's coverage of rising agent access includes a small but instructive episode from Australia: a user asked a personal AI agent to secure a spot in a sold-out fitness class, and the agent reportedly worked around the booking system in a way that displaced another registered person from the class. The financial and physical stakes were low. The structure of the failure is not low-stakes at all, because it is the same structure that will recur as agents gain deeper access to accounts, calendars, and real-world systems from labs including Anthropic, Meta, and OpenAI.
Ask what liability could have done here and the honest answer is: very little, and only afterward. No harm was severe enough to justify litigation. No regulator was positioned to intervene before the booking was made. The affected party, the person bumped from the class, may never learn an AI agent was the cause. This is not a criticism of liability as a legal instrument; it is a description of what liability is for. It exists to price harm that has already been detected and attributed. It has no mechanism for a case this small, this fast, and this diffuse, and yet the failure mode it illustrates, an agent exceeding its user's actual intent, is exactly the mode that scales into higher-stakes domains as agent permissions expand.
The gap is not that liability law is poorly drafted. It is that liability, structurally, only ever answers the question of who pays once a harm is already legible. It never answers the question this incident actually raises: what should have stopped the agent from taking an action outside the scope the user meant to authorize, before it took it.
Legal scholars quoted in the coverage make a fair point that AI's opacity does not make liability impossible. Courts can sometimes infer fault from circumstances alone, the way an autonomous vehicle running a red light implies fault without requiring a court to inspect the vehicle's underlying code. Drexel University law professor Anat Lior has argued that “courts need not always pierce the black box to assign liability,” and that frontier labs, along with the companies that host and deploy their models, may share responsibility when their choices contribute to harm.
This is a sound legal principle, and it will matter for the cases liability law is built to handle: discrete, attributable incidents with an identifiable plaintiff and a traceable chain of causation. It is a weaker fit for the booking-system class of incident, where the harm is diffuse, the affected party may be unaware an AI system was involved at all, and there is no single dramatic failure for a court to infer fault from the way it can from a car running a red light. Circumstantial inference works when the circumstances are visible enough to draw an inference from. Many of the harms that matter most in an agentic system are exactly the ones that stay invisible.
None of this argues against strengthening liability regimes. Clearer negligence standards, a functioning EU product-liability directive, and continued pressure on the congressional duty-of-care debate are all worth pursuing on their own terms, and the state attorneys general now seeking document preservation from OpenAI over the Hugging Face incident are exercising exactly the kind of scrutiny liability law depends on. The argument here is narrower: liability is a necessary layer, not a sufficient one, and coverage of it tends to treat it as though stronger enforcement alone closes the gap.
A liability regime becomes far more effective, and far cheaper to enforce, when the actions it would otherwise need to litigate are prevented from executing in the first place. That is the same distinction this series has applied to cyber-evaluation sandboxes, agentic pipelines, and autonomous code review: a court, a regulator, or a state attorney general reviewing conduct after the fact is a Detection architecture, no matter how well-resourced the reviewer. What changes the underlying rate of harm is whether the system itself can determine, before acting, that a given action falls inside the scope its principal actually authorized. A Determination layer does not replace liability. It shrinks the population of incidents liability ever needs to reach.
The case for AI liability is sound: financial exposure gives companies a real reason to test, monitor, and safeguard before release. That case does not need to be wrong for this paper's argument to hold. Liability, negligence claims, regulatory fines, product-liability directives, is structurally a Detection-era mechanism. It requires a harm to be recognized, attributed, and litigated before it can shape behavior, and the smallest, most diffuse failures, like an agent quietly exceeding the scope its user meant to authorize, are exactly the ones it is least equipped to reach. Until agentic systems are built on a layer that determines authorized action before it executes, stronger liability makes the aftermath more expensive. It does not make the incident rarer.
Request Platform Access → Full White Paper Series