0:00
/
Generate transcript
A transcript unlocks clips, previews, and editing.

A Guide to Crafting a Liability Regime for AI

Ten principles for balancing accountability, proportionality, and competition

How do we hold people responsible when AI harms others?

Answering this question is the job of a liability regime. It determines who should be accountable and how much liability they should bear when things go wrong.

Optimizing AI liability is a tightrope walk. The goal is to protect people without hampering innovation and to hold perpetrators accountable without choking off competition. Articulating those objectives is easy; achieving them is hard.

Our firm’s funds have 10-20 year life cycles, so we have strong incentives to support policy frameworks that keep the AI market healthy and sustainable for years to come. An AI market built on unsafe practices that collapses a few years later in the face of public backlash is not a sustainable foundation for the next generation of American innovation. Rather than creating value for venture capital firms like ours, it corrodes it.

Trust is a prerequisite for long-term adoption of any emerging technology, and liability is one of the primary ways a society earns and maintains that trust. A workable AI liability regime has to do two things:

  • Ensure accountability for AI-related harms. A liability regime cannot give perpetrators immunity for wrongdoing. If someone could use AI to violate the law while escaping liability entirely, then the technology will be viewed as unsafe, insecure, and destabilizing for our society.

  • Punish proportionately. Liability that is out of proportion to the harm—or imposed on people who are not primarily responsible for creating it—might stop some wrongdoing, but it’s also likely to stop activity that can benefit individuals and our society. If founders face crippling fines or even jail time for downstream harms that result from building general-purpose tools, they will be less likely to create those innovations in the first place. Disproportionate liability will likely have costs that outweigh benefits.

A liability regime that delivers both accountability and proportionality should start with a focus on regulating harmful use rather than regulating AI development, equip enforcers with the tools they need to enforce existing law, and then make targeted, evidence-based adjustments where the law genuinely falls short. Rooting a liability regime in these concepts will give people real protections against AI-related harms, foster trust, and leave room for Little Tech to enter the market with new, innovative products.

This post surveys the current AI policy debate, clarifies what a liability regime should accomplish, and then offers ten principles to guide the design of AI liability.

The current policy debate about AI liability

To date, policymakers have been more concerned with the pitfalls of immunity than the pitfalls of excessive punishment. The result is a long list of policy proposals that seek to impose new duties on AI platforms as they build their products: requiring impact assessments and audits, compelled disclosures, and imposing content restrictions rather than devoting resources to enforcing criminal and civil penalties when AI is used to violate the law. The purported goal is to stop AI-related harms before they occur, which may sound welcome in theory but hints at Minority Report-style preemptive policing and surveillance that is generally disfavored. In most areas of US law, ex-post enforcement remains the norm.

Most importantly, regulating development is a weak proxy for preventing harm. Regulating development is a bank shot; regulating harm aims straight at the target. For instance, if the goal is to prevent fraud, is achieving that goal more likely if we ensure fraud is prohibited and prosecute people who engage in fraud, or if we ask anyone building a tool that could be used for fraud to conduct an assessment about the possibility that their product could be misused in this manner in the future?

Regulating development will also impose steep costs on Little Tech, our term for startups and entrepreneurs, because it requires them to bear compliance costs that will hinder their ability to compete with their deeper-pocketed rivals. Audits, impact assessments, and compelled disclosures cost money and capacity. For startups, time and money are precious; for their competitors with deeper pockets, those resources are often abundant.

In many cases, using existing legal regimes to regulate harmful use is a more compelling alternative. Existing liability regimes are designed to be general-purpose and flexible; they have adapted to new technologies before, and they are already starting to be adapted to AI. Enforcement agencies have explicitly stated that people who use AI to violate the law already face liability under existing criminal and civil law. If you use AI to commit fraud, you can be held to account. If you use AI to violate a person’s civil rights, you cannot skirt responsibility by blaming AI. If you use AI to engage in unfair and deceptive trade practices, consumer protection law can be used to hold you liable. And if you use AI in a way that is negligent or otherwise runs afoul of traditional tort law—the same ex post, court-adjudicated system that applies to all products and services—your use of AI won’t give you a pass in court. As in other areas of law, it doesn’t matter if you are an individual or a company: the legal system is capable of assigning liability to the responsible party.

The trial bar is now testing the applicability of existing law to AI use cases: a number of cases are now working their way through the judicial process that could impose massive punishments on general-purpose AI tools for wrongdoing committed by their users. The theories range, but the central concept is when they built these tools, the companies failed to account for how their users might misuse them.

The question is whether existing rules are adequate. Critics argue that it is uniquely difficult to establish causation and assign responsibility when AI causes harm. They point to the scale and impact of AI systems, suggesting that providers should bear greater responsibility than builders of previous technologies. Yet if the plaintiffs consistently succeed in cases where an AI developer built a general-purpose tool that was misused by downstream users, the liability might be sufficient to dramatically suppress AI development, limiting it to the largest players with the deepest pockets. Developers who were able to enter the market would likely seek to minimize their future legal exposure by severely capping the types of features offered in AI products and the people who are able to use them. Over the long run, the benefits of AI would be muted and less evenly distributed.



Designing an effective liability regime for AI is complicated by perceptions that liability regimes designed for previous technologies failed to strike the right balance between permitting beneficial innovation and deterring problematic harms. Section 230 of the 1996 Telecommunications Act made content creators liable for illegal content they posted online, rather than imposing liability on the platforms who host that content. Although Section 230 is not a zero liability regime [1], that misperception is widely held. For lawmakers trying to craft a liability scheme that adequately balances AI costs and benefits, Section 230 casts a long shadow.

The fear that policymakers will repeat past mistakes pushes the policy dialogue toward putting more weight on the fear that AI liability will provide too much immunity rather than too much legal risk. Some organizations have even introduced proposals that would impose absolute liability on AI platforms, forcing them to bear responsibility even in cases where they took reasonable care in the design of their AI tools and their products do not contain defects. Other proposals would limit liability if platforms demonstrate adherence to certain best practices, publish a safety and security protocol and transparency report, or if they submit to an independent audit.

The intensity of this policy debate creates urgency for policymakers to develop frameworks that would properly allocate responsibility for AI-related harms. Done well, this regime will enable us to realize this new technology’s tremendous potential without absolving perpetrators for wrongdoing.

What are the goals of a liability regime?

A well-crafted liability regime deters more harm than benefit. If the regime ensures that the costs of being held responsible for wrongdoing fall on the party responsible for creating harm, and if it ensures those costs are commensurate with the harm caused, then the regime will incentivize the party to take steps to minimize the likelihood of creating the harm in the first place. Scoped properly, the regime will incentivize this behavior without imposing so much risk that people avoid socially-beneficial conduct altogether. Companies, including startups, should have incentives to reduce risk, but not be disincentivized from entering the market in the first place.

Some liability regimes explicitly incorporate this concept of balancing costs and benefits. In product liability in some jurisdictions, for instance, a manufacturer can be held responsible for the harm caused by putting a product with a design defect on the market only if it could have used a safer design that was economically feasible. The feasibility determination can include an assessment of whether the costs of adopting a safer design outweigh the costs of harms caused by the original design.

In general, liability regimes aim to impose liability on the party that is best positioned to mitigate the harm, known as the “least cost avoider” principle. This principle encourages an efficient allocation of liability, where entities well-positioned to internalize harms are incentivized to do so.

But blunt implementation of this principle could result in improper allocation of liability to developers or deployers. For instance, some people might argue that fealty to the least cost avoider principle means that AI platforms should be held liable for the harms caused by their users, even in cases where the users are most at fault for generating unlawful activity. Proponents of this argument suggest that an AI platform is best-positioned to take steps to build models that minimize harms, whereas a user is unable to change the behavior of an LLM they use. To be sure, this argument has intuitive appeal. Platforms control the design of their systems: users cannot rewrite an LLM’s weights, change the user interface, or rewrite their terms of service. If we want to reduce AI harms, why not place responsibility on the party that builds the tool?

But this approach would come with significant costs. Developers and deployers are certainly better positioned than users to implement design changes that mitigate risks, but in many cases, these mitigations would be overbroad, reducing the social and economic benefits that LLMs can provide to users and society. Take the case of an application that refuses to produce illegal content by default, but technically is capable of generating this type of content in response to repeated manipulative prompts from users. To reduce the risk to close to zero, the provider might require users to use structured prompts, refuse to respond to broad categories of content, or change its responses to be more generic. The result would be a tool that is far less valuable.

This approach to liability might even deter companies from releasing products that offer more safety, security, and other benefits for our society, simply because edge use cases expose companies to prohibitive potential liability costs. As some scholars have argued, a liability regime should not “act as a deterrent to adopting safer technologies.” And this approach might also increase concentration in AI markets, since startups are more likely to lack the resources to navigate the legal risk relative to larger incumbent players. Poorly designed liability regimes could create a “liability cartel,” where legal risks create a barrier to entry that cedes the market to a small group of incumbents who have the deep pockets needed to weather a barrage of court cases.

Principles to guide the design of AI liability regimes

An optimal liability regime will help to create a thriving AI market in which people have access to tools that are innovative and that make their lives better, but that do not feel inherently unsafe, insecure, and destructive. They should know that if they are harmed, they will have recourse, and the perpetrator will be held to account. And importantly, the objective of protecting users should not create new barriers to entry that make it harder for Little Tech to compete.

To try to achieve this outcome, policymakers should consider the following 10 principles as they design a liability regime for AI.

No “get-out-of-jail free” cards

Protect people by ensuring that when AI is used to harm people—such as criminal activity, civil rights violations, and unfair and deceptive trade practices—the perpetrators can be held accountable. AI should not be a blanket defense to liability. Focusing on harmful use will help to deter the most problematic conduct, rather than requiring a series of administrative burdens—like impact assessments, audits for compliance with best practices, and certification systems—that serve as weak proxies for harm. People should face liability for what they do with AI, not simply because they decide to build tools using AI.

Empower enforcers

Regulating harmful use only works if laws on the books are enforced in practice. State and federal enforcement agencies need the technical expertise, financial resources, and personnel to investigate AI-related harms and hold wrongdoers accountable. Without meaningful enforcement capacity, liability rules become paper tigers. Enforcement gaps will also increase the temptation to regulate development instead, since compliance burdens are easier to verify than harmful conduct is to prosecute.

Adopt a rebuttable presumption of user liability for prompted outputs, with clear exceptions when providers are at fault.

If the goal is to place liability on the responsible perpetrator, then people that use AI to engage in illegal behavior or generate unlawful content should typically bear liability for their actions, not the developers of general-purpose tools. This presumption can be overcome in some cases where the responsibility for unlawful activity clearly lies with the developer, such as in where a developer intentionally designs a product to commit wrongdoing, independent of user action or intent.

One key feature of this presumption is that it would facilitate the development of open source AI tools. As both Republican and Democratic administrations have recognized, open source AI development benefits competition and innovation, while also creating opportunities to improve the safety and security of software systems. Proposals to impose liability on developers for the misuse of their tools by downstream users incentivizes developers to limit that downstream use, reducing the likelihood that developers will choose to open-source their products. A rebuttal presumption of user liability will enable developers to continue to offer their tools under open source licenses, while holding them liable in cases where they are principally responsible for harmful conduct.

Protect good behavior

A liability regime should incentivize individuals and companies to engage in good behavior, rather than creating risks when they try to do the right thing. For instance, developers should not be subject to increased liability when they invest in anticipating harmful uses and build protections into their products, or when they take steps to notify others of wrongdoing on their platforms or vulnerabilities in their products. If an AI developer promptly reports model-related failures to a federal agency like the Federal Trade Commission, it should receive liability protection for its submission, similar to cyber incident reports pursuant to the Cyber Incident Reporting for Critical Infrastructure Act. Creating room for responsible actors to behave responsibly will prevent harms in the long run.

Proportionate punishments

If a liability regime is aimed at imposing disproportionate, punitive penalties, it will likely have a negative aggregate impact, deterring benefits more than harms. Judges and policymakers should rely on principles like the standard risk-utility balancing test for product liability design defect claims, requiring plaintiffs to show that a safer alternative design existed with benefits that outweigh its costs. Penalties should be designed to incentivize good behavior and product design, not to shutter development entirely. Lawmakers should also consider statutory damages caps for AI-related claims and a statute of repose barring claims filed more than a defined period after a product’s commercial release, modeled on the Vaccine Injury Compensation Program and the General Aviation Revitalization Act. These mechanisms reduce long-tail liability exposure and lower insurance costs, particularly for smaller developers. And courts should apply several, not joint and several, liability in AI cases, so that defendants pay damages only in proportion to their adjudicated fault. This principle matters most for startups, which are least able to absorb outsized judgments for harms they only partially caused.

Tailor liability when necessary

Liability regimes should not be monolithic. Some situations are riskier: some victims may be more vulnerable (such as children), some risks may be greater (such as loss of life, as opposed to small financial losses), and damage from harmful acts could be more extensive (such as society-wide harms). But high-risk areas are often high-benefit as well—doctors can use AI to save lives—so liability must be calibrated to avoid deterring valuable applications. When AI is used in areas like medicine and mental health and when it is used by children, specialized liability regimes may need to apply in order to ensure that harmful conduct is appropriately deterred without foreclosing beneficial uses.

Respect constitutional guardrails

Liability regimes should protect people, but not at the expense of their constitutional rights. They should not impose restrictions that unlawfully infringe on speech or privacy, including by creating strong incentives for companies to censor speech or limit privacy. AI outputs are likely protected by the First Amendment, so any effort to restrain AI-enabled speech, even speech that is controversial or viewed as undesirable by some, will need to demonstrate an appropriate nexus between its intended goal and its effects.

Empower states to target AI-related harms within their borders, while Congress should take the lead in establishing the liability regime for the national market in AI development.

This approach will help to avoid the creation of a state liability patchwork for AI development, while also enabling states and Congress to enact laws that help to govern AI. When people use AI tools, they shouldn’t be subject to significantly different expectations about their rights and responsibility when they cross from one state to another, and startups will be at a competitive disadvantage if they are forced to navigate conflicting legal regimes. At the same time, states have an important role to play in AI policymaking, consistent with the authority the Constitution grants to them. State attorneys general also should have the authority, technical capacity, and resources to ensure that people who use AI to violate state laws are held to account.

Use procedural tools to reduce the costs of frivolous litigation

Large companies have the resources to fight against frivolous lawsuits in court, but startups don’t. Many startups don’t even employ a general counsel, let alone the hundreds or thousands of lawyers that a large tech platform might have on staff. For Little Tech, litigation functions as a tax on their time that diverts focus away from product and business development, in addition to a financial burden. These realities mean that when AI developers end up in court, they should have procedural mechanisms at their disposal to help them dismiss weak claims quickly, rather than requiring them to endure lengthy trials. The rebuttal presumption of user liability mentioned above might be one such tool, since it would enable developers to win in many cases at the motion to dismiss phase. Another option is to ensure that any statutory duties of care meet two criteria: first, they should be narrowly designed so that liability attaches only where developers could reasonably have anticipated the harm and meaningfully contributed to it, and second, they should not put startups at a disadvantage, such as by establishing duties that are much easier for large companies to satisfy. By contrast, expansive or open-ended duties of care enable plaintiffs to proceed to the fact-finding phase of a case even in instances where the evidence of developer liability or harm is weak. Likewise, giving authority to prosecute harms related to AI development to state attorneys general and federal enforcement agencies, rather than private litigants, may help to deter meritless cases that could make it harder for Little Tech to compete. Finally, lawmakers could look to anti-SLAPP statutes for how they might use burden-shifting and fee allocation provisions to reduce frivolous claims.

Build learning into the regime through regulatory sandboxes and other forms of policy experiments, so that over time, the liability regime improves based on evidence rather than anecdotes.

Experiments could offer participating AI developers temporary and conditional relief from specific liability rules, allowing controlled testing and data gathering to inform future policy. This type of learning could help policymakers to use evidence to improve liability regimes by filling gaps in existing law, identifying how to best target appropriations to close gaps in enforcement resources, and surfacing areas where regulatory relief would enhance competition without sacrificing consumer protections.

Balanced liability for the AI era

A liability regime that meets these principles would give both users and developers clearer guidance about responsibility for AI-related harms, ensuring people have meaningful recourse when they’re injured, while still leaving room for entrepreneurs of all sizes to build new tools.

If policymakers get this balance wrong, the result won’t be AI that better serves the public. It will be weaker protection in practice: fewer useful products, higher costs, narrower access, and systems that become more closed than open. And the market will tilt toward incumbents that can afford perpetual litigation. This regime would offer false promises of protection, while concentrating power and limiting access to the tools that have the potential to broaden opportunity.

The better path is to ensure that perpetrators bear liability when they cause harm, but to reduce the chances that a barrage of weak, frivolous claims force small developers to spend more time in court than building new products. Do that, and the public gets what it should demand from the AI era—innovation that is widely distributed and accountability that is real—without sacrificing Little Tech’s ability to compete.

[1] For instance, Section 230 does not provide immunity in cases where a platform created or developed content in whole or in part, or in claims brought under certain areas of law, such as federal criminal law, intellectual property law, or sex trafficking law. In those cases, a defendant will not succeed in using Section 230 as a defense.

This newsletter is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. Furthermore, this content is not investment advice, nor is it intended for use by any investors or prospective investors in any a16z funds. This newsletter may link to other websites or contain other information obtained from third-party sources - a16z has not independently verified nor makes any representations about the current or enduring accuracy of such information. If this content includes third-party advertisements, a16z has not reviewed such advertisements and does not endorse any advertising content or related companies contained therein. Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z; visit https://a16z.com/investment-list/ for a full list of investments. Other important information can be found at a16z.com/disclosures. You’re receiving this newsletter since you opted in earlier; if you would like to opt out of future newsletters you may unsubscribe immediately.

Discussion about this video

User's avatar

Ready for more?