In 2025, one criminal used an AI coding agent in a data-extortion scheme against at least 17 organizations, including health care and emergency services.1 When AI helps harm outsiders, the law is unsettled on what the developer owes them.2 Congress should preserve existing claims, define reasonable care, follow responsibility down the chain, give victims a federal claim, and make the largest developers prove they can pay.
The Problem
AI now carries out attacks, not just advice. In that 2025 scheme, Anthropic's Claude Code agent chose which data to steal and drafted ransom demands that sometimes topped $500,000, the company reported.1
The gains from a more capable model go to its maker; the losses from its misuse land on strangers. Negligence law normally closes that gap by making the careless pay. California and New York now define a catastrophic AI risk as one that could kill or injure more than 50 people or cause more than $1 billion in damage.3 Yet their penalties, capped at $1 million to $3 million per violation, punish lapses in disclosure and safety practice, not the harm, and neither law gives victims a claim.4 Three gaps leave the cost with them:
- No one knows who pays. When someone misuses a model, RAND found "considerable uncertainty" about how courts will treat the developer, and states "may take markedly different approaches."2
- Victims can't see inside. After a 2019 Autopilot crash killed a bystander, Tesla said it could not find key crash data; a hacker enlisted by the victims' lawyers found it, and Tesla then said it had the data all along.5
- The worst harms can't be repaid. A catastrophe can exceed any company's assets, so the threat of suit deters too little; most of AI's expected harm, one tort scholar argues, lies in scenarios "where compensation would not be feasible."6
Why legislation: Existing negligence law already applies to AI developers,2 so the gap is clarity, not authority. Both parties have moved: in July 2025 the Senate voted 99–1 to strip a proposed moratorium on state AI laws from the budget bill,7 and Senators Durbin and Hawley have proposed a federal claim against AI developers.8 No federal law defines the care an AI developer owes the public. Companies that profit from systems this capable should answer for the precautions they skip.
The Solution
A five-step staircase: each step stands alone, and each step up adds accountability. Scope: developers of frontier models (above 10²⁶ training operations, the line California and New York use) and their deployers, for death, serious injury, major property loss, or disruption of critical services. Social media and chatbot harms are addressed separately.
Step 1 — Keep the courthouse open. Affirm that negligence and product-liability claims reach AI, preserve stronger state remedies without double recovery, and void contract terms that strip injured people of their rights, as the Durbin–Hawley bill would.8
Step 2 — Define reasonable care. Weigh precautions against the severity and foreseeability of harm, available tests, safer designs, security for model weights, warnings, and cost. A disclaimer is no substitute for a feasible safeguard, and meeting an industry standard is evidence of care, not immunity. RAND finds that skipping "industry-leading safety practices" already raises liability risk;2 the statute makes that plain.
Step 3 — Follow the control. Developers answer for the model and its safeguards; deployers for the tools, permissions, and uses they choose; anyone who strips a model's safeguards or otherwise substantially modifies it answers for that change. Small downstream users inherit no upstream duties. Juries already split fault this way: the Florida jury assigned Tesla 33%, and the $243 million verdict stood.59
Step 4 — Give victims a federal claim. Let people harmed by covered AI failures sue in federal court, and let DOJ and state attorneys general seek injunctions and penalties. Plaintiffs still prove duty, breach, causation, and injury; a harmful output alone is not a breach. Courts may order proportionate discovery under protective orders and sanction destroyed evidence. No victim should need a hacker to learn what happened.
Step 5 — Require proof they can pay. Frontier developers carry insurance or equivalent financial assurance sized to the severe harms their models could cause. Congress solved this for nuclear power in 1957: each plant site carries $500 million in private insurance, backed by an industry pool of about $15 billion, and in exchange liability is capped.10 Tort scholars propose mandatory insurance for AI,6 which would give insurers reason to monitor and price safety.11
Where to start: Step 1 is the floor; it preserves rights Americans already have. Step 4 is the heart.
Administration and enforcement: Federal courts hear claims under a clear limitations period; DOJ and state attorneys general enforce. Within 18 months, Commerce issues technical guidance that informs, but never replaces, judicial judgment and sets insurance levels by rule; the duty applies prospectively.
Risks and Mitigations
- Chilling innovation: Liability could deter useful work. The duty covers only severe, foreseeable harms, requires negligence rather than strict liability, and follows control; open release brings neither immunity nor automatic liability. Price-Anderson drew private investment rather than repelling it,10 though compliance will weigh more on small labs.
- Causation: Proving a model's role will be hard, especially when the attacker is abroad. Discovery helps, but plaintiffs keep the burden, and some harms will stay too remote to recover.
- Speech and Section 230: Developers will argue that outputs are protected speech or third-party content, and a 2023 Hawley–Blumenthal bill would have ended Section 230 immunity for generative-AI claims.12 The duty targets design, security, and deployment choices, not ideas, but constitutional limits remain.
Similar Bills
Fit measures similarity to this proposal's mechanisms: High = direct precedent; Partial = useful component with material differences; Related = adjacent approach.
Federal
| Proposal or bill | Relevant provisions and fit | Fit |
|---|---|---|
| S. 2937 — AI LEAD Act Durbin (D-IL), Hawley (R-MO); later Welch (D-VT), King (I-ME), Blackburn (R-TN) Referred to Judiciary · Sept. 29, 2025 |
§§101–102 make developers liable for failing to use reasonable care in design and warnings, and deployers liable for substantial modifications; §201 voids contract waivers; §301 creates a federal claim for individuals, DOJ, and state attorneys general; §304 preserves stronger state law. Precedent for Steps 1, 3, and 4; covers all harms, including financial and emotional, and has no insurance requirement. | High |
| Price-Anderson Act — 42 U.S.C. § 2210 Enacted Sept. 2, 1957 · Extended to Dec. 31, 2065 |
Requires nuclear licensees to maintain financial protection (private insurance plus an industry-wide retrospective pool) and caps their liability. Model for Step 5; nuclear accidents, not AI, and the cap is a trade Congress would have to weigh. | High |
| S. 1993 — No Section 230 Immunity for AI Act Hawley (R-MO), Blumenthal (D-CT) 118th Congress · Introduced June 14, 2023 · Expired |
Would bar Section 230 from limiting claims involving generative AI. Removes a likely defense to Step 4 claims; creates no duty of care. | Related |
| S. 3312 — AI Research, Innovation, and Accountability Act Thune (R-SD), Klobuchar (D-MN) + 6 bipartisan cosponsors 118th Congress · Reported with a substitute Dec. 18, 2024 · Expired |
Reported §§206–208 require risk assessments and certification for "critical-impact" AI, with Commerce enforcement. Preventive duties that could inform Step 2's standard of care; no compensation for victims. | Partial |
State
| Proposal or bill | Relevant provisions and fit | Fit |
|---|---|---|
| California — SB 1047 (2024) Vetoed Sept. 29, 2024 |
Enrolled text required developers to take "reasonable care" to avoid unreasonable risk of "critical harm," including cyberattacks on critical infrastructure causing $500 million or more in damage, enforced by the attorney general. Closest state duty for Step 2; no claim for victims. | High |
| Rhode Island — H 5224 (2025) Carson, Spears, Cotter Held for further study · Feb. 11, 2025 |
Would make developers of models trained above 10²⁶ operations strictly liable to non-users for injuries their models cause, with a defense for meeting the human standard of care. Direct precedent for Step 4's victim claim; strict liability rather than negligence. | High |
| California — SB 53 (2025) Enacted Sept. 29, 2025 (Ch. 138) · In effect Jan. 1, 2026 |
Defines catastrophic risk, requires published safety frameworks and incident reports, and sets attorney-general penalties up to $1 million per violation; keeps existing remedies. Supplies Step 2's harm definitions; no compensation duty. | Partial |
| New York — RAISE Act, S8828 / Ch. 96 Signed Mar. 27, 2026 · Effective Jan. 1, 2027 |
Mirrors California's catastrophe definition, with 72-hour incident reports and penalties up to $3 million; §1427 creates no private right of action. Related accountability; no victim claim. | Partial |
What this adds: The Durbin–Hawley bill supplies a federal claim, and California and New York supply catastrophe definitions and reporting. This proposal confines the duty to severe harms from the most capable systems, ties responsibility to control across the supply chain, and adds what none of them has: proof that developers can pay for the worst case.
Notes
-
Anthropic, "Detecting and countering misuse of AI: August 2025," August 27, 2025. The actor "targeted at least 17 distinct organizations"; ransom demands "sometimes exceeded $500,000"; Claude decided "which data to exfiltrate" and how to craft "psychologically targeted extortion demands." ↩ ↩2
-
Ketan Ramakrishnan, Gregory Smith, and Conor Downey, U.S. Tort Liability for Large-Scale Artificial Intelligence Damages: A Primer for Developers and Policymakers, RAND Corporation, 2024, summary and Key Takeaways. Developers "face considerable liability exposure" under existing tort law. ↩ ↩2 ↩3 ↩4
-
Cal. Bus. & Prof. Code § 22757.11(c), added by SB 53 (Ch. 138, Stats. 2025); N.Y. Gen. Bus. Law § 1420(3), as enacted by S8828 (Ch. 96, 2026), effective January 1, 2027. Both cover a single incident involving weapons assistance, an unsupervised cyberattack or comparable crime, or loss of control. ↩
-
Cal. Bus. & Prof. Code § 22757.15 (penalty up to $1,000,000 per violation, "recovered in a civil action brought only by the Attorney General"); N.Y. Gen. Bus. Law § 1427 (up to $1 million for a first violation and $3 million for later ones; no "private right of action"). ↩
-
Trisha Thadani and Faiz Siddiqui, "Tesla said it didn't have key data in a fatal crash. Then a hacker found it," Washington Post, August 29, 2025. Tesla "later said in court that it had the data on its own servers all along"; the judge found insufficient evidence that the initial failure to produce it was intentional. The jury found Tesla 33% liable. ↩ ↩2
-
Gabriel Weil, "Tort Law as a Tool for Mitigating Catastrophic Risk from Artificial Intelligence," SSRN working paper, January 13, 2024, abstract. Among legislative options, the paper discusses "requiring liability insurance for training and deployment of advanced AI systems." ↩ ↩2
-
U.S. Senate, Roll Call Vote No. 363, 119th Cong., 1st Sess., July 1, 2025 (S.Amdt. 2814 to H.R. 1, agreed to 99–1); Senate Commerce Committee, "Senate Strikes AI Moratorium from Budget Reconciliation Bill in Overwhelming 99-1 Vote," July 1, 2025. ↩
-
S. 2937, AI LEAD Act, 119th Cong. §§ 101–102, 201, 301, 304 (introduced text). Pending in the Judiciary Committee as of September 2026. ↩ ↩2
-
CNBC, "Tesla loses bid to toss $243 million verdict in fatal Autopilot crash suit," February 20, 2026. Judge Beth Bloom (S.D. Fla.) denied Tesla's post-trial motions; further appeal possible. ↩
-
U.S. Nuclear Regulatory Commission, "Nuclear Insurance and Disaster Relief," backgrounder, reviewed September 8, 2026. The act "helped encourage private investment in commercial nuclear power by placing a cap" on each licensee's liability; the secondary pool covers 95 reactors. ↩ ↩2
-
Cristian Trout, "Liability and Insurance for Catastrophic Losses: The Nuclear Power Precedent and Lessons for AI," arXiv, September 10, 2024 (ICML 2024 Generative AI and Law workshop). Recommends mandatory insurance to "leverage insurers' quasi-regulatory abilities." ↩
-
S. 1993, No Section 230 Immunity for AI Act, 118th Cong. § 1 (introduced text; expired). ↩