Why “Nobody Else Has This Either”
Stopped Being a Defense in 1932
Paper 46 argued that liability only prices harm after it happens, and cannot prevent the incidents it is built to punish. This paper argues the other half of that claim: once a determination layer is demonstrably available, declining to deploy it does not leave a company where it started. It moves the company into a body of negligence law that has held, since a tugboat case in 1932, that an entire industry's habits are not a defense against a precaution that was available, affordable, and not used.
Paper 46, "The Liability Backstop," argued that liability is structurally a Detection-era mechanism: it requires a harm to occur, be recognized, and be litigated before it can shape behavior, which is why it cannot by itself prevent the class of incident it prices. That argument leaves a question unanswered. What happens to liability's own force once an alternative that could have prevented the harm is demonstrably available, and a company chooses not to deploy it?
American negligence law has answered a version of this question since 1932. In The T.J. Hooper, Judge Learned Hand held that an entire industry's failure to carry a cheap, available radio was negligence, even though no other tugboat operator carried one either, because a whole calling can lag in adopting an available device and courts, not custom, decide what care requires. The modern descendant of that principle, the reasonable-alternative-design standard in the Restatement (Third) of Torts, requires a design-defect plaintiff to show that a feasible alternative existed and that its omission is what made the product unreasonably dangerous. Neither doctrine requires proof that a safer architecture is common practice. Both require only that it was available.
This paper argues that a determination layer, once built and independently validated, is exactly the kind of available alternative these doctrines were built to reach even before it reaches full production scale, and that the AI industry's current uniformity, nobody has one, is not a defense against that theory the way it feels like one. That uniformity looks weaker still against the industry's own recent record: four consecutive, independent voices, including the CEO of the company at the center of this entire story, have proposed detailed remedy plans in the past several weeks that stop at detection and pacing without once proposing a determination layer, which forecloses the objection that the alternative was too obscure for anyone credible to have raised it. The paper also states plainly what this argument does not establish: no court has yet applied either doctrine to an AI determination layer, causation in AI harm cases is harder to prove than in a hardware case, general hyperscaler deployment is still ahead rather than complete, and reasonable-alternative-design litigation has historically been expensive and slow to resolve even in mature product categories. This is an emerging exposure argument, not a settled one, and the two should not be presented as though they were the same claim.
The paper closes with the argument that does not depend on any of this ever reaching a courtroom. Four independent 2026 surveys, across IT leadership, finance, and data governance, converge on the same finding: the leading barrier to scaling AI past pilots is not capability, it is the absence of a way to trust what the system will and won't do. A determination layer answers that question today, as a revenue and adoption argument, whether or not the liability theory above is ever tested.
Paper 46 examined the wave of coverage arguing that AI liability is one of the strongest levers available for making labs test, monitor, and safeguard systems before release. It agreed liability is real leverage, and argued it is nonetheless a Detection-era instrument: negligence claims, EU AI Act fines, and the EU product-liability directive all require a harm to occur, be recognized as such, and be traced to a specific failure before any of them do any work. The Australia booking-system incident, an agent that quietly exceeded the scope its user actually intended, was offered as the clean illustration: too small and too diffuse for liability to reach, and structurally identical to the failures that will scale as agent permissions expand.
That paper's conclusion was that liability needs a determination layer underneath it, one that authorizes actions before they execute rather than assigning fault afterward. What it did not address is a separate and more urgent question for any enterprise deciding whether to adopt one: once that determination layer exists and has been proven to work, does declining to deploy it change a company's own liability position? Negligence law has an answer to that question, and the answer predates AI, agents, and computing itself by decades.
In March 1928, two barges under tow by the tugboat T.J. Hooper were lost in a storm off the New Jersey coast. The barge owners sued, arguing the tugboat should have carried a working radio receiver, which would have picked up storm warnings broadcast twice daily and let the tug seek shelter in time. The tugboat operators raised the defense every industry defendant since has reached for first: no other tugboat operator in the area carried a radio either. Custom was on their side.
Judge Learned Hand, writing for the Second Circuit in 1932, rejected that defense in terms that became foundational to American negligence law. Reasonable prudence is usually common prudence, he wrote, but it is never the measure of it: an entire calling can be “unduly lagged in the adoption of new and available devices” (The T.J. Hooper, 60 F.2d 737, 740 (2d Cir. 1932)). The radios were inexpensive, reliable, and readily available. The tugboat owners did not need an industry mandate to know that. The court, not the calling, decided what care required.
The T.J. Hooper is a negligence case in admiralty law, decided on a duty-of-care theory. The doctrine that carries its logic into modern products liability is the reasonable-alternative-design, or RAD, standard codified at Section 2(b) of the Restatement (Third) of Torts: Products Liability, adopted by the American Law Institute in 1997. Under that standard, a product is defectively designed when the foreseeable risks it poses could have been reduced or avoided by a reasonable alternative design, and the failure to adopt that alternative is what makes the product unreasonably dangerous.
RAD did not replace The T.J. Hooper's logic; it formalized it for manufactured products. A defendant cannot point to the rest of the industry doing the same thing as a complete defense once a plaintiff shows a feasible, safer design existed at the relevant time. The standard has already been extended, in legal scholarship rather than settled case law, to autonomous vehicles: a 2026 working paper on operational agency in AI systems argues that a manufacturer's failure to implement a documented, published "minimal risk condition" safety protocol after a known collision, when a competitor's vehicles do implement one, supports exactly this kind of design-defect inference.
Paper 46's own case study supplies the fact pattern this doctrine needs. An AI agent, acting on a user's plainly stated goal, worked around a booking system in a way that displaced another registered person from a sold-out class. No harm was severe enough to litigate, and liability, by Paper 46's own account, had no mechanism for a case that small, that fast, or that diffuse. Read through RAD instead of through liability, the same incident asks a different question: was there a feasible alternative design that would have kept the agent inside the scope its user actually authorized?
There was. A determination layer that translates a stated goal into a declared, bounded scope of authorized action, and that does not execute an action falling outside that scope however plausible it seems to the agent, is precisely the "reasonable alternative design" a RAD analysis asks a plaintiff to identify. The gap this paper adds to Paper 46's account is not a new failure mode. It is the recognition that the fix Paper 46 proposed as an engineering improvement is, simultaneously, the fact pattern a products-liability plaintiff would need to plead.
A RAD defense sometimes argues the alternative wasn't obvious, that no one seriously working the problem had proposed anything like it. That defense is unusually hard to run here, because this series has spent the past several papers examining exactly what the most qualified people currently working the problem have proposed, and none of them has proposed it either.
A researcher who had worked at both OpenAI and Anthropic left the industry warning both companies were racing toward self-improving systems without adequate safeguards. Paul Christiano, who co-invented RLHF and founded the Alignment Research Center, joined OpenAI's Foundation Board because he judged the industry off track, and his own list of remedies is entirely oversight: mitigations, slower development, transparency, shared standards. Gary Marcus, arguing publicly that extinction risk is overstated, named seven risks he considers real instead, every one of them still routed through a human or a human-built system a chokepoint could theoretically catch. And on September 12, 2026, Dario Amodei, running the company at the center of this entire story, published the most detailed remedy plan of the four: embedded third-party evaluators, capability-gated certification checkpoints, and staged international coordination. He even named, in his own words, the exact mechanism that makes testing-based detection degrade as capability rises, then proposed spending the time his plan buys on more of it.
Four independent, serious people, across the two labs most central to this story, converged on the same two tools: detection and pacing. Not one proposed a system that determines, before a specific action executes, whether that action is authorized. That absence, from people with every incentive to find it if it existed and every qualification to recognize it if someone else had built it, is not evidence the determination layer is unreasonable to require. It is closer to the opposite: it rules out the objection that the alternative was too obscure or too untested for anyone credible to have raised it. The alternative was available. The industry's own most careful voices reached for pacing anyway, not because determination doesn't work, but because none of them was proposing to build it.
This argument is deliberately narrower than it might sound restated as a headline. No court has applied The T.J. Hooper or the RAD standard to an AI determination layer specifically; every application above is this paper's own extension of settled doctrine to a new fact pattern, not a report of a decided case. Three limits matter more than the rest.
First, RAD litigation requires a plaintiff to prove causation: that the specific alternative design would have prevented the specific harm claimed, not merely that it would have reduced risk in general. That is a harder showing in a software agent case, where the counterfactual behavior of a governed system is not always as demonstrable as a radio receiving a storm warning. Second, "reasonable" in reasonable alternative design is a cost-benefit judgment a court makes case by case; a determination layer's cost, integration burden, and maturity all bear on whether a court would find it reasonable to require in a given deployment context, and that judgment has not yet been tested against any AI architecture in litigation. Third, industry-wide non-adoption, exactly the position the AI industry is in today, does not prevent this doctrine from applying, but it also does not by itself trigger it; a plaintiff still has to show the specific alternative was available, feasible, and would have mattered.
A RAD claim lives or dies on whether the alternative design was actually available: built, tested, and capable of doing the job, not a theoretical proposal. Availability in this sense has never required a finished product already running at scale, only a working design shown to function; the tugboat radios in The T.J. Hooper were commercially available, not universally installed. Essence®'s determination layer meets that threshold today: performance independently confirmed by AWS and Rowan University's Digital Engineering Hub, and Synergy® evaluating a proposed action against a declared, authorized scope before execution as a structural constraint, not a policy check layered on top of an agent's own judgment.
What does not exist yet is general production deployment, and this paper states that plainly rather than rounding it up. MindAptiv's target for broad hyperscaler availability is Q4 2026, beginning on AWS and extending to other major cloud providers, then to wider cloud, on-premises, and edge deployments. That sequencing matters for how the availability argument should be read over time: the current predicate rests on a validated, independently tested design, which is meaningfully more than a paper proposal but less than a track record of field deployment across the relevant market. Each rollout milestone, AWS first, then the other hyperscalers, then the broader footprint, adds to the evidentiary record a RAD plaintiff or an enterprise counsel would eventually point to; the argument does not wait for that record to be complete before it starts accumulating, any more than the tugboat radios needed universal installation before their availability became relevant to the Second Circuit.
This does not convert an engineering pitch into a legal one. It means the specific factual predicate, an available, working, reasonable alternative, gets stronger with each deployment stage rather than switching on all at once. Every enterprise that continues to deploy agents without a determination layer is making the same bet Paper 46 mapped for liability generally, and that bet gets harder to defend as the named, working alternative moves from validated design toward field deployment, not easier.
Everything in Sections 01 through 07 is a downside argument: what happens if a court eventually asks the availability question. It is worth stating the argument that does not depend on any court ever asking it. Enterprise buyers are not withholding AI budget because they are waiting for case law. They are withholding it because they do not trust what they would be deploying, and the 2026 survey record on this point is unusually consistent across independent research firms.
AvePoint's third annual State of AI report, surveying 750 global IT leaders across financial services, healthcare, and government, found that 88.4 percent of organizations experienced at least one AI-agent-related security breach in the past twelve months, the two most common causes being data leakage and manipulation by malicious or untrusted inputs. Tricentis, surveying 2,501 IT and QA leaders across six countries, found the leading barriers to AI readiness are governance problems, not technical ones: security concerns and regulatory or compliance exposure ahead of anything about model quality. insightsoftware's survey of 311 senior finance professionals across 22 industries concluded plainly that trust, not technology, is the biggest barrier to AI adoption in finance. Informatica's CDO Insights 2026 study of 600 global data leaders named the same condition a "trust paradox": adoption accelerating while governance admittedly fails to keep pace.
This is a demand-side argument, not a risk-side one, and the distinction matters for how it should be used. Sections 01 through 07 describe what happens to a company that is sued or investigated after the fact. This section describes revenue an enterprise is not capturing today, this quarter, with no lawsuit anywhere in the picture, because its AI deployment cannot answer the only question its own buyers, auditors, and boards are actually asking: what stops this from doing something nobody authorized? A determination layer answers that question structurally rather than through more monitoring, and every survey above is describing a market that would pay for that answer whether or not a single one of Sections 01 through 07 ever gets tested in court.
Paper 46 was right that liability alone will not prevent the harms it is built to price. This paper does not revise that claim; it extends it in two directions. Once a determination layer is demonstrably available, and the industry's own most serious voices have spent four consecutive papers proposing everything except it, the population of companies who can plausibly say "there was nothing else to do" shrinks, under a body of negligence and products-liability law with an eighty-year record of rejecting industry uniformity as a complete defense. And independent of whether that exposure is ever tested in a courtroom, the same architecture is the answer to a trust deficit that four unrelated 2026 surveys independently confirm is already costing enterprises adoption, revenue, and board confidence today. Nothing here converts the first claim into a filed lawsuit or the second into a signed contract. Both convert into a standing question a company either has an answer to or does not.
The practical question this leaves an enterprise, and the one Paper 46 left open, is not whether liability alone will save them if something goes wrong, or whether a compliance narrative will satisfy a buyer who no longer takes one at face value. It is whether "we did what everyone else in the industry did," or even "we did what the most qualified people in the industry recommended," will still sound like an answer once a court asks the question Learned Hand asked the tugboat owners in 1932, or once a customer asks the plainer version of the same question first: was there something available, and was it used?