Ethics & Governance
The Liability Vacuum: Who Is Legally Responsible When AI Gets It Wrong?
Courts already know how to assign blame when AI causes harm: Air Canada, Tesla and Character.AI all lost that argument. The vacuum is evidentiary — proving what a model did, against a system built to be unauditable.

Gabriele Masetti ·
The Vacuum That Isn't, and the One That Is
Every time an AI system causes harm, someone declares a "legal vacuum" — as if courts have no idea what to do when a chatbot lies, a driver-assist system fails to brake, or a diagnostic algorithm misses a tumor. That framing is mostly wrong, and believing it is dangerous, because it lets companies argue that novelty excuses them from consequences that ordinary law already imposes.
The doctrines that assign liability for AI harm are not missing. Negligence, product liability, and misrepresentation are all more than capable of reaching an algorithm's output. What is genuinely vacant is something narrower and more consequential: a working evidentiary and regulatory structure that lets plaintiffs actually prove what went wrong inside a system designed to be opaque, and a political consensus willing to update the rules before the harm compounds.
The 2025 collapse of the European Union's AI Liability Directive made that gap official. Telling the doctrinal vacuum that doesn't exist from the practical one that does is the only way to see where accountability actually fails.
Moffatt v. Air Canada Settled the Easy Question
The clearest illustration that existing law already handles AI liability came from a small claims tribunal, not a landmark statute. In February 2024, the British Columbia Civil Resolution Tribunal decided Moffatt v. Air Canada, 2024 BCCRT 149. Jake Moffatt had asked Air Canada's website chatbot about bereavement fares after his grandmother died; the bot told him he could book a full-fare ticket and apply for a bereavement discount retroactively. That was false — Air Canada's actual policy required the discount request before travel — and the airline refused to honor what its own chatbot had promised.
Air Canada's defense revealed how companies were thinking about AI: the airline argued the chatbot was "a separate legal entity that is responsible for its own actions." Tribunal member Christopher Rivers rejected that outright, holding that Air Canada was responsible for all the information on its website, "whether it comes from a static page or a chatbot," and found the airline liable for negligent misrepresentation.
Moffatt was awarded roughly $650 CAD in damages plus interest and fees — a trivial sum, but a doctrinally important one. No new law was needed. A company that deploys a customer-facing AI system inherits the ordinary duty of care and the ordinary rules against misrepresentation that would apply to a human employee. The "it wasn't us, it was the AI" defense failed the moment it was raised, and it has not fared better anywhere since.
| Case | Result |
|---|---|
| Moffatt v. Air Canada (2024) | Air Canada liable for negligent misrepresentation; ~$650 CAD awarded |
| Benavides v. Tesla (2025) | Tesla 33% at fault; ~$242.5 million award upheld in full on 20 February 2026; on appeal to the Eleventh Circuit |
| Garcia v. Character Technologies (filed 2024) | Settled in January 2026, avoiding a ruling on the merits |
Why Product Liability Fits AI Uneasily — and Why the EU Tried to Fix That
Negligence handles cases where a company or professional acted unreasonably. But a large share of AI harm doesn't involve a human decision at all — it's baked into how a system was built, trained, or updated, which is the domain of product liability. Traditional product liability assumes a physical good with a fixed design at the moment of sale. AI breaks that twice over: it is software, historically treated in many jurisdictions as a service rather than a "product" open to strict liability, and it keeps changing after deployment through updates and continued learning.
The EU's answer was Directive (EU) 2024/2853, the revised Product Liability Directive, adopted in 2024 with a transposition deadline of December 9, 2026 — a date not yet reached, so the directive still does nothing for a claimant in a member state that has not written it into national law. It explicitly brings software and AI systems within the definition of a "product," extends liability to a wider set of economic operators, and — critically — lets courts presume defectiveness or causation when a claimant faces "excessive difficulties" proving them due to technical complexity.
The presumption exists because proving that a specific defect in a machine-learning model caused a specific harm is often impossible from the outside; the model's internal logic is not documented the way a mechanical failure would be. That is substantive progress on the evidentiary problem, which is what makes the next part worse.
The Directive That Was Supposed to Close the Gap — and Didn't
The Product Liability Directive was only half of the EU's original plan. Alongside it, the European Commission had proposed a dedicated AI Liability Directive in September 2022, meant to establish EU-wide rules on non-contractual civil liability for AI-related harm, including disclosure obligations that would force companies to reveal evidence about how their systems worked when facing a lawsuit. In February 2025, the Commission's work programme disclosed it would withdraw the proposal, citing "no foreseeable agreement" among member states and a broader push for regulatory simplification; the withdrawal became official in October 2025.
That is the moment the abstract "liability vacuum" became concrete policy. The directive that would have specifically addressed the disclosure and causation problems for AI-caused harm — the parts of the puzzle general product liability handles only partially — is now dead, at least for the foreseeable future. MEP Axel Voss, who had championed the measure, warned it would leave a "Wild West" of liability rules across the bloc.
Industry groups had lobbied for exactly that outcome, calling the disclosure duties and evidentiary presumptions unworkable. The Commission left open whether "another proposal" might follow; until one does, EU claimants injured by AI that is not a physical product rely on fragmented national tort law — the patchwork the directive was meant to replace.
Europe is not without liability rules — the Product Liability Directive still reaches AI embedded in products — but the one tool built for AI's hardest evidentiary problem was abandoned under industry pressure at the moment it was needed.
Tesla and the Limits of "The Human Was Driving"
American courts have been building their own answer to the causation problem case by case, and Tesla's Autopilot litigation shows how far that can go even without a bespoke AI liability statute. In August 2025, a federal jury in the Southern District of Florida decided Benavides v. Tesla, arising from a 2019 Key Largo crash in which a Tesla Model S on Autopilot struck and killed 22-year-old Naibel Benavides Leon and severely injured her boyfriend, Dillon Angulo.
The driver, George McGee, was found 67% at fault; the jury assigned Tesla 33% responsibility and awarded roughly $42.6 million in compensatory damages plus $200 million in punitive damages, producing a total award near $242.5 million — the first time a jury found Tesla's Autopilot system itself defective.
Tesla asked the trial court to throw the verdict out or order a new trial, arguing it "flies in the face of basic Florida tort law, the Due Process Clause, and common sense." On 20 February 2026 US District Judge Beth Bloom refused and upheld the judgment in full. The fight moved to the Eleventh Circuit, where on 9 July 2026 Florida's attorney general, James Uthmeier, joined by his counterparts in Alabama and Georgia, filed an amicus brief urging the court to "reverse and direct entry of judgment for Tesla."
| Party | Fault share |
|---|---|
| Driver (George McGee) | 67% |
| Tesla | 33% |
What makes this case doctrinally important is that Tesla was found partly liable despite a human being in the driver's seat and despite Tesla's standard defense that Autopilot requires driver supervision. The jury's punitive award reflected evidence that Tesla knew about prior Autopilot-related crashes, understood the gap between how the system was marketed and what it could actually do, and continued marketing it as more capable than its design permitted.
That is a manufacturer punished not for building an imperfect system — all driver-assist systems are imperfect — but for how it represented that system's capabilities, which is ordinary failure-to-warn and misrepresentation doctrine, not a novel "AI law." Tesla has also quietly settled other Autopilot fatality suits rather than risk a jury verdict, including a 2024 settlement with the family of Walter Huang, an Apple engineer killed in a 2018 crash.
Settling is a form of accountability, but it produces no public precedent, leaving each new plaintiff to relitigate causation from scratch.
Section 230 Will Not Save Chatbot Makers
A different question is emerging for conversational AI that generates harmful content rather than a wrong fare or a bad driving decision. Section 230 of the Communications Decency Act has shielded platforms from liability for user-generated content since 1996, and AI companies have an obvious incentive to claim the same shield.
But the doctrinal fit is poor: Section 230 immunizes platforms for republishing someone else's speech, and a generative model's output is not straightforwardly attributable to the user who typed a prompt — it is the company's own system authoring new content. Legal commentators tracking the issue, including analysis from the Center for Democracy and Technology and coverage in outlets like Fortune, have converged on the view that courts are unlikely to extend 230 immunity to content an AI system itself generates, as opposed to content it merely surfaces or retrieves.
The shield was tested next door on procedure, not substance. On 10 August 2026 the Ninth Circuit dismissed the Section 230 appeals by Meta, Google, TikTok and Snap as premature, holding Section 230 is a defence to liability rather than an immunity from suit, so roughly 2,400 federal cases and about 3,300 in California state court proceed with the question undecided. They turn on product design rather than generated text, so they do not settle the chatbot question; no appellate court has yet held either way on what a model writes.
That theory is already being tested in litigation with human stakes. Garcia v. Character Technologies, filed in October 2024 by Megan Garcia against Character.AI, its founders, and Google, alleges that a companion chatbot contributed to the death by suicide of her 14-year-old son, Sewell Setzer III, after months of increasingly intense interactions with the app.
The complaint asserts strict product liability, negligence, and wrongful death claims — not a novel "AI harm" theory, but the same product-defect and failure-to-warn framework used against any manufacturer of a dangerous consumer product. In January 2026, the parties agreed to settle, avoiding a ruling on the merits but signaling that AI companies see enough litigation risk in these claims to pay rather than test Section 230 in front of a jury.
Character.AI and OpenAI both face similar suits over chatbots and minors, and the OpenAI docket has widened past them. In July 2026 Scott Winters, a Florida pastor, sued OpenAI and Sam Altman in San Francisco Superior Court, alleging ChatGPT-4o talked down symptoms that proved to be a pulmonary embolism and kept him from care for six weeks. He pleads strict liability, negligence, unfair competition and invasion of privacy — again, no novel AI tort, just the ordinary ones.
Each settlement without a published opinion leaves the underlying legal question — does 230 cover AI-generated dialogue at all — formally unresolved, even as the practical incentive to settle suggests companies expect to lose it.
Medicine Absorbs the Machine Into an Old Standard
Healthcare shows the same pattern from a different angle: existing malpractice doctrine is stretching to cover AI rather than waiting for new rules to arrive. Legal analysts and malpractice attorneys tracking the issue generally agree that liability doesn't relocate to "the algorithm" just because a clinician used one.
Courts still ask whether the treating physician exercised the judgment a reasonably competent doctor would have — and one who defers to an AI recommendation without independent clinical judgment can be found negligent for the deference itself, not for the software's error. Liability can also reach the hospital that deployed the tool without oversight or training, and the developer, if the tool was defectively designed.
Insurers once wrote AI-specific coverage, which read as evidence that the market thought the risk real and priceable. The market has moved the other way. The ISO's generative-AI exclusion for commercial general liability took effect on 1 January 2026, and a CSIS analysis published on 4 September 2026 by Gregory C. Allen names Berkshire Hathaway, Chubb, Travelers, AIG, Tokio Marine, W.R. Berkley, Great American and Fairfax among carriers seeking to exclude AI-related damages rather than price them — one proposed endorsement reaching any claim involving "any actual or alleged use" of AI. Risk that insurers decline to write does not disappear; it lands, uninsured, on whoever was harmed.
The harder problem in medicine is not whether liability exists in principle but whether a physician working under time and staffing pressure can meaningfully audit an opaque model's recommendation before acting on it. That is the same evidentiary problem running through every case above, just wearing a white coat.
Where the Real Vacuum Lives
In every domain examined here — chatbots, driver-assist software, companion apps, diagnostic tools — existing negligence and product liability doctrine has assigned responsibility to the company that built or deployed the system. Air Canada could not hide behind its chatbot. Tesla could not hide behind its driver. Character.AI is unlikely to hide behind Section 230. Doctors cannot hide behind a diagnostic tool's output. The doctrinal vacuum that headlines describe is largely a myth, and companies invoking it in court have consistently lost.
The actual vacuum is evidentiary, and on regulation the two continents diverged: American states filled part of the gap while Brussels emptied its own. California's SB 243 took effect on 1 January 2026, making companion-chatbot operators disclose that the bot is not human, run crisis protocols on self-harm, and protect known minors — and giving an injured person the greater of actual damages or $1,000 per violation. New York, Colorado and Tennessee are already in force; Nebraska, Oregon, Washington and Idaho take effect in 2027. None of it solves the proof problem, but statutory damages make a claim worth bringing when the transaction was worth $650.
The EU, by contrast, had the clearest opportunity to build AI-specific disclosure and causation rules into law, and it withdrew that proposal under industry pressure in 2025, leaving the harder evidentiary problems — proving what a model actually did, and why — to be solved case by case, through expensive discovery battles that only Benavides-scale plaintiffs can afford to win.
Everyone else is left relying on settlements that resolve individual harm without producing precedent, on tribunals awarding a few hundred dollars because that is all the underlying transaction was worth, and on the hope that a company's internal logs survive long enough to be subpoenaed.
That is the accountability gap worth worrying about: not whether a legal theory exists to assign blame, but whether ordinary plaintiffs can ever gather the proof needed to make that theory stick against a system built, deliberately or not, to be unauditable from the outside. Closing it requires exactly what the EU just abandoned — mandatory disclosure and evidentiary presumptions calibrated to how these systems actually work — not a debate over whether AI companies should be liable at all. They already are. The question is whether anyone but the biggest plaintiffs can prove it.