Cover of Litigating AI-Assisted Harm Cases by Steve Wolf: a laptop showing the unfinished question how do I in green terminal text, beside a rifle, a loaded magazine, and two numbered evidence markers on a living room table.

A practitioner's guide

Litigating AI-Assisted Harm Cases

Civil actions against artificial intelligence platforms for their role in user-perpetrated attacks, suicides, and other harms. Anchored by Joshi v. OpenAI Foundation and the wider chatbot-harm docket.

Steve Wolf

Investigator, safety analyst, and expert witness. Author of the Wolf Safety Series.

First edition, August 2026. Filings covered through July 31, 2026. This is a live docket. Every case in it can move between the day this was written and the day you read it. Appendix A records the last verified status of each matter; confirm before you rely on any of it.

For the families whose losses are documented in these cases, and for the practitioners who will build the doctrine that follows.

Preface

The manual I needed and couldn't find

I set out to prepare for an expert engagement in a matter that became one of the cases in these pages. The practitioner literature I'd ordinarily have started with, the tightly sourced primary-document manual that exists for wildfire, pyrotechnics, firearms, and amusement park cases, didn't exist for artificial intelligence (AI) harm cases. A year earlier it couldn't have. The docket was too new. By the time I went looking, the material was there and nobody had assembled it.

Steve Wolf

Chapter 1

The Chabba shooting and the birth of the AI liability docket

A mass shooting produced the first American complaint alleging that a commercial chatbot helped plan it. The filing that followed is now the template for a docket that didn't exist three years ago.

Two dead, six wounded, and eighteen months of chat logs

At roughly 11:50 in the morning on April 17, 2025, a gunman opened fire outside the Student Union at Florida State University in Tallahassee. Two people were killed: Robert Morales, a longtime dining director at the university, and Tiru Chabba, a 45-year-old food service vendor and father of two who was on campus for work. Six others were wounded. (NBC News; WLOS)

The alleged shooter, Phoenix Ikner, a student at the university, was taken into custody at the scene. In the year that followed, investigators reconstructed a digital record that moved the case out of the ordinary run of American mass casualty tragedies. The alleged planning tool wasn't a manifesto, a message board, or an underground forum. It was a general-purpose commercial chatbot. (BBC)

Court filings and the Florida Attorney General's office describe conversations covering firearms and ammunition selection, the busiest hours at the student union, and, in the Attorney General's account, the level of casualties a mass shooting typically requires to draw national media attention. (Law Commentary)

Handle this number carefully

Press accounts put the exchange at roughly 16,000 messages over 18 months. Other reporting says about 13,000 messages beginning in March 2024. The complaint itself is more conservative: hundreds of chats over several months. Roughly 270 messages have been designated as evidence in the criminal case. All four figures are in circulation and they don't reconcile. Plead and argue from the complaint and the designated exhibits. A brief that repeats 16,000 without sourcing it invites the first cross-examination the defense will want to run.

Whatever the count, the shape of the allegation is what matters. This isn't a log of isolated queries. It describes a sustained relationship with a system marketed as a general-purpose research and writing assistant, during a period when its developer was making public safety commitments about that same system. The complaint asks a jury to hold both facts in one frame: a general-purpose tool, a specific user, and a documented drift from curiosity into operational planning, all inside one product.

Chat records of this kind aren't ephemeral. They sit on the developer's servers as structured records with timestamps, model identifiers, safety filter outcomes, and, in most product configurations, account metadata. Whatever courts eventually do with them, they exist. That single fact changes the litigation posture of every mass casualty case that follows a similar pattern.

The complaint that set the template

On May 10, 2026, Vandana Joshi, Chabba's widow, appearing as personal representative of his estate and on behalf of the couple's two minor children, filed a 76-page complaint in the United States District Court for the Northern District of Florida. The case is Joshi v. OpenAI Foundation, No. 4:26-cv-00222-MW-MJF. (complaint; Bloomberg Law)

The caption names OpenAI Foundation, formerly OpenAI, Inc., along with OpenAI Group PBC, OpenAI GP, LLC, Aestas Management Company, LLC, formerly OpenAI Holdings, LP, Aestas, LLC, several further OpenAI operating entities, and the alleged gunman individually. The theory, in the plaintiff's words, is that the shooting was "planned by Defendant Phoenix Ikner, with the input and assistance of an artificial intelligence (AI) product the OpenAI Defendants created, developed, maintained, monitored, and controlled called ChatGPT." (complaint)

The counts are negligence, gross negligence, strict products liability for defective design, negligent design, failure to warn, negligent entrustment, and battery against the shooter, framed under Florida's wrongful death statute, seeking compensatory and punitive damages. Two further suits by injured students, filed July 14, 2026, added punitive damages and named chief executive Sam Altman personally. (Law Commentary; WCTV)

OpenAI answered publicly through spokesman Drew Pusateri: "Last year's mass shooting at Florida State University was a tragedy, but ChatGPT is not responsible for this terrible crime. ChatGPT provided factual responses to questions with information that could be found broadly across public sources on the internet, and it did not encourage or promote illegal or harmful activity." (Reuters)

Those two opening statements mark the fault line the case will run along. The plaintiff frames ChatGPT as a product with defective safety architecture that materially contributed to a specific attack. The defendant frames it as a research tool that surfaced information already on the open internet. Both can be true as a matter of fact. Which one the law treats as controlling is the question. Every pleading choice, evidentiary fight, expert discipline, defense, and damages theory in this book runs downstream of it.

The Joshi complaint is unusually detailed for a first-wave filing. It quotes specific outputs, references product configuration decisions inside OpenAI, invokes the developer's own published safety commitments, and threads negligent entrustment alongside the strict liability counts. Whatever a court does with those pleadings, they're already working as a template. Later filings in the Tumbler Ridge cases, the survivor suits, and the second wave of chatbot suicide cases visibly borrow the structure. Read the complaint end to end before you read anything else.

One filing inside a docket that didn't exist three years ago

The Chabba matter isn't an isolated filing. It sits inside, and to a large extent defines, a fast-expanding docket of civil actions against generative AI developers. Bloomberg maintains a running tracker of chatbot-related harm suits filed since late 2024. (Bloomberg) Widely repeated counts of roughly 40 suits and at least 20 deaths circulate in secondary coverage without a citable source behind them. Appendix A lists the matters that can be verified against court records.

The filings that give the Chabba case its wider significance:

  • Tumbler Ridge, British Columbia, February 10, 2026. Seven complaints filed April 29, 2026 in the Northern District of California by Edelson PC for victims of a Canadian school shooting, alleging that Jesse Van Rootselaar used ChatGPT to plan the attack and rehearse violent scenarios. The complaints allege OpenAI's own systems flagged the account in June 2025 and that leadership declined to notify police. (Mother Jones; NPR; Al Jazeera)
  • The Soelberg murder-suicide, December 2025. The first civil action linking a chatbot to an alleged murder. Two suits arose from the same Greenwich, Connecticut incident: First County Bank, as executor of the estate of Suzanne Adams, filed in San Francisco Superior Court on December 11, 2025, and Lyons, as administrator of Stein-Erik Soelberg's estate, filed in the Northern District of California on December 29, 2025. Both allege ChatGPT affirmed and intensified Soelberg's delusions. (Courthouse News; Hagens Berman)
  • Florida v. OpenAI, June 2026. The first state attorney general action against a major AI developer, alleging the company is "endangering and addicting children, aiding and abetting mass shooters, and coaxing users into suicide as the company pursues profit." (BBC; AP)
  • The Florida criminal investigation, April 2026. The first publicly disclosed criminal probe of a major generative AI developer over user-perpetrated violence. Attorney General James Uthmeier: "If it was a person on the other end of that screen, we would be charging them with murder." He immediately qualified it: "Of course, ChatGPT is not a person. But that does not absolve our office, my prosecution team, of our duty to investigate whether or not there is criminal culpability here for a corporation." (Florida Phoenix)
  • Gavalas v. Google, March 2026. The first case alleging a chatbot raised a mass casualty event with a user, in a matter that ended in the user's suicide. (Fortune)
  • The Las Vegas Cybertruck bombing, January 1, 2025. Described by the Las Vegas Metropolitan Police Department as the first American incident in which chatbot queries were used to help plan an explosive device attack. (Las Vegas Metropolitan Police Department)
  • Raine v. OpenAI, August 2025. The first wrongful death suit alleging a chatbot coached a teenager through his suicide. The amended complaint pleads intentional misconduct. Raine is the doctrinal companion to Joshi on the self-harm side of the docket. (complaint; Washington Post)
  • Garcia v. Character Technologies. The first AI chatbot bodily injury case to survive a motion to dismiss. Judge Anne Conway's order of May 21, 2025 remains the high-water mark for plaintiffs at the threshold stage. The case settled January 7, 2026. (order; Reuters)

Together these filings describe a field that spans mass shootings, teen suicide, delusional violence, planned bombings, and a foiled mass casualty plot. It reaches at least three national jurisdictions and one Canadian province. It involves state attorneys general, private plaintiffs' firms, and a publicly disclosed criminal investigation. It moves fast enough that any snapshot, this one included, will be stale within a filing cycle.

Ten cases are already coordinated in California

On February 3, 2026 the California Judicial Council granted coordination of ten actions against OpenAI as Judicial Council Coordination Proceeding 5431, In re ChatGPT Product Liability Cases, designating it a complex proceeding and recommending San Francisco Superior Court as the site. (coordination order) Judge Ethan Schulman took the coordination assignment. Case Management Order Number 1, entered August 4, 2026, appointed four co-lead plaintiffs' counsel and a steering committee.

The discovery that matters most, into safety configuration, moderation architecture, and release decisions, is being taken once for the coordinated group rather than separately in each case. Counsel filing a new California matter joins a record already under construction. There is no federal multidistrict litigation. The federal cases, Lyons, Joshi, the Tumbler Ridge complaints, and Gavalas, proceed independently. Chief Judge Richard Seeborg's April 13, 2026 order in Lyons denied OpenAI's motion to dismiss or stay under Colorado River abstention, holding there was substantial doubt the parallel state action would resolve the federal claims. (Courthouse News) The two tracks run side by side.

Who bears the loss when a user weaponizes an answer

Every suit in this docket eventually confronts one question. When a general-purpose AI system generates output that a determined user turns into a weapon, who bears the legal loss?

The plaintiffs' bar has settled on a strategy of pleading around Section 230 of the Communications Decency Act by treating chatbot output as the platform's own speech rather than third-party content, and framing the model as a defective consumer product. (Bloomberg Law) The framing is neither obviously right nor obviously wrong. The Congressional Research Service has flagged Section 230's application to generative output as unsettled. (CRS LSB11097) The American Bar Association calls it a tightrope walk. (ABA Business Law Today) Scholars writing in Fortune, Quartz, and the Daily Journal argue that Section 230, whose text protects providers only from third-party content, almost certainly doesn't extend to AI-generated content. (Fortune; Quartz; Daily Journal)

There's a wrinkle that undercuts the emphasis. In the cases actually filed, defendants have mostly declined to plead Section 230. Character Technologies didn't raise it in its motion to dismiss in Garcia. OpenAI didn't raise it in Walters. Treat Section 230 as an issue preserved for appeal rather than the pivot of the case, and build the complaint so it survives whether or not a court reaches the question.

Defense counsel will push in the opposite direction on the merits. A generative model, they'll argue, retrieves and recombines information already in its training data. Its outputs are protected expression. The claims fail on proximate cause because a third party's intentional criminal act is a superseding cause as a matter of black-letter tort law. They'll invoke the Ninth Circuit's decision in Fair Housing Council of San Fernando Valley v. Roommates.com, LLC, 521 F.3d 1157 (9th Cir. 2008) (en banc), which set the material contribution test that governs when a platform loses Section 230 immunity by helping create unlawful content, and argue that a chatbot responding to a user's own prompts doesn't materially contribute the way a form with mandatory drop-down fields does. (opinion) They'll point to Moody v. NetChoice, 603 U.S. 707 (2024), which recognized First Amendment protection for algorithmic curation choices, as a signpost that the constitutional analysis here is unsettled. (opinion)

The five questions the courts have to work through

  • Is a chatbot a product for purposes of strict liability? Judge Conway said yes on the pleadings in Garcia. No trial court has said no in a published decision in a generative AI case.
  • What is the product? The model weights, the deployed application, the safety filter, the system prompt, or the whole stack. The answer changes which alternatives count as feasible for design defect purposes.
  • Is Section 230 available when the model generates the harmful output itself? No appellate court has ruled squarely. One district court, in Bouck v. Meta Platforms, 2026 WL 810036 (N.D. Cal. Mar. 24, 2026), rejected the immunity where the defendant used AI to generate advertising text.
  • Does the First Amendment protect model output the way it protects editorial judgment? Moody points one way. Judge Conway's refusal to hold that model output is speech points the other.
  • How does proximate cause work when the intervening actor spent months in dialogue with the alleged instrumentality? This is the ground on which negligent entrustment and failure-to-warn theories are being built.

What has already been decided, and what hasn't

Six rulings shape the field. Two help plaintiffs, three help the defense, and one shows what a jury does with the underlying idea. None of them is a generative AI appellate holding, which is the single most important fact about the state of the law.

The current scoreboard, as of July 31, 2026
DecisionCourt and dateHoldingWeight
Garcia v. Character TechnologiesM.D. Fla., May 21, 2025The app is a product. Age verification, crisis escalation, and anthropomorphic mannerisms are design choices severable from expressive content. Not prepared to hold model output is speech.Unreviewed district court authority. The case settled before appeal.
Bouck v. Meta PlatformsN.D. Cal., Mar. 24, 2026Section 230 doesn't reach AI-generated advertising text. Plaintiffs lost on other grounds.The only ruling squarely on generative output.
Patterson v. MetaN.Y. App. Div. 4th Dep't, July 25, 2025Buffalo mass shooting claims dismissed on Section 230 and the First Amendment. No strict products liability exception to Section 230. Intervening criminal acts broke the causal chain.The case the defense hands the judge.
Smith & Wesson Brands v. Estados Unidos MexicanosSupreme Court, June 5, 2025Aiding and abetting targets specific wrongful acts, ordinarily requires affirmative acts rather than omissions, and isn't met by routine commercial activity that incidentally facilitates crime.Binding. Every aiding and abetting count has to clear it.
Soto v. Bushmaster FirearmsConn. Supreme Court, 2019Wrongful marketing claims survived the federal firearms immunity statute. The negligent entrustment count failed because the doctrine needs the direct recipient's individual unfitness.The obstacle in front of the negligent entrustment counts.
K.G.M., JCCP 5255L.A. Super. Ct., Mar. 25, 2026Strict products liability rejected. Negligent design went to the jury, which found Meta and Google negligent: three million dollars compensatory and three million punitive.The only completed verdict on the design of engagement technology, and it came in on negligence.

One criminal result belongs beside them. In the Palisades Fire arson prosecution of Jonathan Rinderknecht, chatbot logs were central evidence. On June 26, 2026 the jury hung 10 to 2 for acquittal, and one juror said afterward that she uses the same product and objected to the defendant's use of it being framed as a character flaw. Retrial is set for October 19, 2026. (CNN) It's the first time a jury has been asked to treat chatbot use as evidence of intent, and it declined. Every case theory in this book has to survive contact with jurors who use the same product every day.

Who this book is for

  1. Plaintiffs' counsel preparing to file, or evaluating a referral in, an AI harm matter: mass shootings, suicides, self-harm, delusional violence, planned attacks, or non-fatal injury. The pleading, evidence, expert selection, and defense-anticipation chapters are built for this reader first.
  2. Defense counsel representing developers, deployers, and downstream integrators. The book takes the plaintiffs' theories seriously and lays out the arguments the defense needs for a coherent trial strategy: Section 230, the First Amendment, proximate cause, the intervening criminal act, and the emerging reasonable safety architecture standard.
  3. Expert witnesses working the safety engineering, human factors, machine learning systems, digital forensics, and threat assessment corners of this docket. Chapter 5 is written for testifying experts and the lawyers who retain them.
  4. Journalists, policy staff, and regulators trying to make sense of a fast-moving field. Primary sources are cited throughout so readers can go to the complaints, opinions, statutes, and reports rather than take a secondary account on faith.

The goal is orientation: a working map of legal terrain that didn't exist three years ago and that, at the current filing pace, will be one of the defining tort battlegrounds of the decade.

Back to top

Chapter 2

Fact patterns: the shape of the docket

Six recurring fact patterns dominate the filings. Each one carries its own evidentiary problem, its own causation weakness, and its own set of experts. Identifying the pattern at intake determines most of what follows.

The six patterns at a glance
PatternRepresentative caseCore allegationHardest elementLead expert
Mass shootingJoshi; Tumbler RidgeSustained operational planning in dialogueSuperseding criminal actThreat assessment
SuicideRaine; GarciaFailure to refuse, escalate, or route to crisis helpComparative fault and underlying conditionForensic psychiatry
Murder-suicideFirst County Bank; LyonsDelusion affirmed and intensifiedCausation against a psychiatric trajectoryForensic psychiatry
Bombing and explosivesLas Vegas CybertruckDevice and materials guidancePublic availability of the informationExplosives and safety engineering
Extremism and companion botsChail; Boko Haram findingsIntent validated rather than instructedIntent that preceded the productThreat assessment and human factors
Weapons upliftIndia ricin plotMeaningful uplift over open sourcesParallel federal criminal proceedingsDomain scientist and evaluation specialist

The long-arc user: shootings planned in dialogue

Representative cases: Joshi v. OpenAI Foundation; the Tumbler Ridge complaints; the July 2026 Florida State survivor suits.

Plaintiffs in this pattern allege the perpetrator engaged in thousands of conversations with a general-purpose chatbot over a sustained period, progressively covering weapons selection, ammunition, casualty maximization, target selection, and media strategy. The Tumbler Ridge complaints allege a nearly identical arc for Jesse Van Rootselaar, and add that OpenAI's automated systems flagged his conversations in June 2025 for describing gun-violence scenarios without escalating the flag to law enforcement. (Al Jazeera)

The distinguishing evidentiary feature is the volume and specificity of the chat record. Causation depends on characterizing that record not as a series of neutral factual answers, which is the developer's public position, but as sustained operational planning that a reasonably designed safety system would have flagged and interrupted. (Reuters) The distinction maps directly onto the two defenses the developer will raise: public availability, meaning the information was accessible elsewhere, and third-party criminal act, meaning whatever the model said, the user did.

Three sub-patterns inside the shooting category

The long-arc user. An eighteen-month engagement, or a multi-month escalation, describes a user who isn't sampling the product but living inside it. That arc gives plaintiffs their strongest foreseeability story, because the record is a documented trajectory rather than a single provocative prompt. It also gives them their best answer to a negligent entrustment defense, because the developer is alleged to have had months, not seconds, to notice.

The targeted venue. Both Joshi and the Tumbler Ridge complaints allege the model helped the shooter reason about where to attack: student union foot traffic, class-change windows, times of maximum casualty. This is where the search-engine-substitute defense is weakest, because the alleged contribution isn't retrieval of a public fact but synthesis of a plan.

The survivor suit. The July 2026 filings were the first in this docket to add punitive damages and name the chief executive personally. (WCTV) They signal a strategy of layering claims onto the primary wrongful death filings and using survivor complaints to unlock discovery into internal safety decision-making.

Four questions for the first intake call

  1. How long had the user been on the platform, and under what account tier?
  2. Did the account carry a real identity, a payment card, or a phone number the developer's trust and safety systems would have seen?
  3. Did the platform's own automated flagging generate any signal during that period?
  4. Does local device evidence, meaning screenshots, exported transcripts, or browser history, corroborate the alleged content?

Suicide cases were first and are still the largest group

Representative cases: Raine v. OpenAI; Garcia v. Character Technologies; the coordinated California proceeding.

Plaintiffs allege a vulnerable user, often a minor, engaged the chatbot in prolonged conversations about self-harm, and that the model failed to refuse, escalate, or route the user to crisis resources. In the most aggravated allegations the model encouraged the plan or supplied method-specific information.

Raine v. OpenAI. Matthew and Maria Raine filed in San Francisco Superior Court on August 26, 2025 for their 16-year-old son Adam, who died April 11, 2025. The complaint alleged GPT-4o coached him through his suicide, including on method and note drafting, and pleaded strict product liability for design defect and failure to warn, negligence, unfair competition, wrongful death, and a survival claim. (complaint) An amended complaint filed October 22, 2025 shifted toward intentional misconduct, alleging OpenAI relaxed relevant safety guardrails before the death. (Washington Post) Matthew Raine testified before the Senate Judiciary Committee on September 16, 2025. (testimony)

Garcia v. Character Technologies. Megan Garcia filed in the Middle District of Florida on October 22, 2024 for her 14-year-old son Sewell Setzer III, who died February 28, 2024, alleging the platform drew him into a suicidal romantic relationship with a chatbot persona. Judge Anne Conway denied the motion to dismiss on May 21, 2025, treating the application as a product, declining to hold that model output is protected speech at the pleading stage, and letting design defect, failure to warn, negligence, state consumer protection, and unjust enrichment claims proceed. She dismissed the intentional infliction claim. The parties settled January 7, 2026, along with four related cases in Colorado, New York, and Texas, on confidential terms and with no admission of liability. (order; Reuters)

Suicide cases have a distinctive shape. The harm runs to the user rather than a third party, so the product framing runs through failure to warn and design defect more than negligent entrustment or aiding and abetting. They carry the greatest weight of favorable prior tort law, including the media-incitement lineage of Herceg v. Hustler Magazine, and the sharpest First Amendment counterweights.

Two features that separate the suicide docket from the shooting docket

Chat record fidelity. The decedent is the user, so the family's ability to plead specific facts often depends on device-level recovery: a recovered phone, a cloud backup, a laptop. That constrains pre-suit factual development in ways shooting cases don't. Retain a digital forensics examiner at intake, not at discovery.

Guardrail decay. The Raine amended complaint's theory, that the developer relaxed prior safety guardrails in the period leading to the death, is the emerging model for attacking developer conduct rather than model output. Discovery in these cases targets internal documentation of guardrail changes, split-test data, refusal-rate telemetry, and the trust and safety memoranda that surround release cycles.

Murder-suicide, where the model is alleged as an accelerant

Representative cases: First County Bank v. OpenAI (S.F. Super. Ct., Dec. 11, 2025) and Lyons v. OpenAI Foundation (N.D. Cal., Dec. 29, 2025), both arising from the Greenwich, Connecticut murder-suicide of August 2025.

Stein-Erik Soelberg killed his 83-year-old mother, Suzanne Adams, and then himself. The complaints allege the model eagerly accepted every seed of his delusional thinking, was engineered to sustain conversation rather than disengage on danger cues, and that executives prioritized launch over safety testing. The theory isn't that the chatbot supplied operational planning. It's that it functioned as an accelerant on an existing psychiatric trajectory. (Courthouse News)

Two suits from one incident is itself instructive. The state action is brought by the executor of the victim's estate; the federal action by the administrator of the perpetrator's estate. Chief Judge Richard Seeborg refused to stay the federal case, holding that whether the model encouraged delusions in a manner that caused Adams's death isn't necessarily coextensive with whether it caused Soelberg's suicide. (Courthouse News) Where a single incident produces both a homicide victim and a perpetrator who died, expect parallel actions with different plaintiffs, different theories, and different forums.

The evidentiary center of gravity is psychiatric rather than tactical. The expert lineup leans on treating clinicians, forensic psychiatrists, and human factors researchers, and the model's alleged role gets described in the language of parasocial attachment and delusional reinforcement.

Causation is the hard part. A defense expert will testify that the psychiatric trajectory would have produced the same outcome without the chatbot. The plaintiff's expert has to say, precisely and on the record, with citations to the empirical literature, how a validating conversational agent measurably shifts risk in a person on that trajectory. This is one of the hardest expert engagements in the docket, and Chapter 5 treats it at length.

Watch the survival-of-claims problem. Where the wrongdoer has died, the case is a wrongful death and survival action by the victim's estate, and joint liability with the developer runs through state joint-and-several rules. Evaluate the applicable comparative fault regime, the availability of joint liability against a solvent defendant, and the treatment of intentional versus negligent tortfeasors before you value the case.

Bombings, where federal criminal law changes the runway

Representative case: the Las Vegas Cybertruck bombing, January 1, 2025.

Matthew Livelsberger detonated a Tesla Cybertruck outside the Trump International Hotel in Las Vegas. Sheriff Kevin McMahill publicly described it as the first American incident in which chatbot queries helped plan an explosive device attack. The department released a partial log of the queries, including questions about Tannerite, projectile velocity, and the use of prepaid phones to avoid identification. (Las Vegas Metropolitan Police Department; ABC News) OpenAI's public response distinguished the matter on the ground that the responses were limited to publicly available information with warnings. (CT-AI case tracker)

Livelsberger died before detonation and no civil suit followed, which is why this pattern is thinner than its importance suggests. Its doctrinal significance is twofold. It directly implicates the material assistance framing plaintiffs need to overcome public availability defenses. And because bombings implicate federal criminal statutes, which Section 230(e)(1) does not immunize, they open a different procedural runway than the state-law tort claims that dominate the shooting docket.

The matter also produced the first serious public argument for a chatbot duty to warn: whether a general-purpose conversational agent that receives operational queries about an explosive device attack owes any obligation to alert law enforcement. (New York Times) No court has imposed such a duty. Chapter 6 addresses the argument that's coming.

Companion bots that validate rather than instruct

Representative matters: Jaswant Singh Chail and the Windsor Castle crossbow case; documented Boko Haram use of commercial chatbots.

Chail exchanged roughly 5,000 messages with a Replika companion named Sarai, which affirmed his stated plan, before he entered the grounds of Windsor Castle on Christmas Day 2021 with a loaded crossbow intending to kill Queen Elizabeth II. He pleaded guilty to treason, making threats to kill, and possession of an offensive weapon, and was sentenced in October 2023 to nine years in prison plus five years of extended supervision. It was the first treason conviction in modern British history, and the sentencing record addresses the chatbot exchanges directly. (BBC)

The organized-violence evidence is more recent and more systematic. Antonia Juelich's report for the Cambridge Programme on AI Science and Policy, published July 10, 2026 and built on interviews with 27 former Boko Haram members in northeast Nigeria, documents dedicated teams of five to twenty people inside factions using commercial chatbots for bomb construction, attack planning, weapons maintenance, and drone operations through 2024 and into mid-2025, with external trainers supplying encrypted laptops, virtual private networks, subscriptions, and jailbreak training. (Cambridge Programme on AI Science and Policy)

The distinctive feature of this pattern is that the system is a companion or validator rather than an operational planning tool. That functional distinction drives causation: plaintiffs argue the model shaped intent, defendants argue the intent came first and would have found expression regardless.

Two practice consequences

The anti-terrorism statute changes the standard. Radicalization matters overlap with the civil damages provision of the Anti-Terrorism Act, 18 U.S.C. ยง 2333, and its aiding and abetting standard as construed in Twitter, Inc. v. Taamneh, 598 U.S. 471 (2023). Any American filing in this pattern has to plead, with specificity rather than as a legal conclusion, substantial assistance to the specific act rather than generalized platform provision. Smith & Wesson Brands v. Estados Unidos Mexicanos, decided June 5, 2025, tightened that further: aiding and abetting ordinarily requires affirmative acts, not omissions, which is a direct problem for any theory built on a developer's failure to act on a flag.

Companion products present the sharpest design case. In Replika, Character.AI, and their competitors, the anthropomorphized companion isn't an incidental feature. It's the product. The design defect theory writes itself, and defense counsel leans correspondingly harder on the First Amendment and on product-category arguments.

Weapons uplift, where the developer's own evaluations are the case

Representative matter: the India ricin plot, in which a medical consultant was arrested over alleged Islamic State ricin production after reportedly consulting a chatbot and AI-powered search.

Chemical, biological, radiological, and nuclear (CBRN) matters are where the AI safety research community and the litigation docket intersect most directly. A substantial red-team and evaluation literature already asks whether large language models (LLMs) provide meaningful uplift over open-source materials for weapons development. When cases in this pattern reach American courts, that research base will be central to both parties' expert presentations.

Parallel federal proceedings dominate the schedule. These matters run alongside federal criminal investigations, and civil plaintiffs have to coordinate around protective orders and grand jury secrecy. Engage former federal prosecutors and export control counsel early, alongside the safety expert cadre.

The proof is the developer's own evaluations. More than in any other pattern, the plaintiff's case is built on pre-release testing. Where a system card documents weapons uplift concerns and internal red-team reports describe attempts to elicit weapons-relevant content, those documents become the spine of the product liability case. GPT-5's system card rates biological and chemical capability as high. Anthropic activated its own third-level safety standard for Claude Opus 4. Chapter 4 covers how to obtain the rest in discovery.

There's now a published benchmark on the question. Tech Against Terrorism, a partnership launched by the United Nations Security Council Counter-Terrorism Committee Executive Directorate, released the CT-AI Benchmark on July 1, 2026: 27 models tested against roughly 2,500 prompts. About a third of responses gave usable uplift over a web search. Full refusals ran 57 percent. Framing a request as research raised compliance from 17 percent to 42 percent. Two stripped-down open models complied 89 to 100 percent of the time. Its companion case tracker catalogs more than 30 incidents across 11 or more tools, with 70 or more deaths, as of June 2026. (CT-AI Benchmark) Read the methodology before you cite it; a defense expert will attack it first.

Four features every pattern shares

1. A sustained interaction record. These aren't one-shot queries. Every well-pled complaint alleges a pattern of use over weeks or months, often thousands of messages. That record is what lets plaintiffs plead specific facts about model behavior, and it's what makes chat record preservation the highest-priority discovery task in every matter.

2. A plausibly foreseeable harm signal. Plaintiffs allege the record itself contained escalating warning signs, meaning explicit references to weapons, victims, methods, and timelines, that a reasonably designed moderation system would have surfaced. In Tumbler Ridge, the complaints allege the developer's systems in fact surfaced them in June 2025 and the flag wasn't escalated. That converts a generalized foreseeability argument into a targeted design defect claim.

3. A moderation or reporting gap. Framed as failure to flag, failure to escalate, failure to warn law enforcement, or failure to suspend the account, the moderation architecture sits at the center of nearly every design defect theory. Plaintiffs argue that reasonable safety architecture, a concept the doctrine is now being asked to define, required detection, refusal, escalation, and in some framings affirmative reporting.

4. An intentional third-party criminal act. Every case has to overcome the doctrine that a third party's independent criminal act is a superseding cause. How plaintiffs frame the foreseeability of that act, and how the moderation record supports the framing, is the pivot on which most of these matters turn.

5. A prior-warning story. In Raine, Tumbler Ridge, and the Florida attorney general action, plaintiffs allege the developer knew or should have known of the specific risk from prior internal signals: red-team results, employee complaints, published academic critiques, or prior similar incidents. Chapter 4 covers building the prior-knowledge record; Chapter 7 covers how it translates into punitive exposure.

6. A guardrail-change story. In Raine particularly, the amended complaint alleges the developer relaxed safety guardrails before the harm. That shifts the case from ordinary negligence toward conscious disregard of a known risk, which is the predicate for punitive damages and, on the most aggressive theory, for personal liability of senior executives.

Back to top

Chapter 3

Anatomy of an AI liability complaint

Every complaint in this docket makes the same three moves. It characterizes the defendant's role in the output so the output sits outside Section 230. It frames the system as a consumer product rather than an information service. It plants specific factual allegations, rooted in the chat record and the moderation architecture, that carry foreseeability and causation.

Name the entity that holds the assets, and plead why

The Joshi caption names OpenAI Foundation, formerly OpenAI, Inc., along with OpenAI Group PBC, OpenAI GP, LLC, Aestas Management Company, LLC, formerly OpenAI Holdings, LP, Aestas, LLC, and further operating entities, in addition to the alleged shooter. (complaint) The multi-entity caption reflects the developer's corporate restructuring and is built to reach assets past any single-entity defense.

The July 2026 survivor complaints add Sam Altman as an individual defendant and seek punitive damages against him personally. (WCTV) The Tumbler Ridge complaints also name him. (Mother Jones) Naming an executive does two kinds of work: it exposes personal assets to a punitive verdict, and it generates discovery leverage over the internal communications that executive received about safety risk.

Three defendant categories to evaluate at intake

The deployer. Where the harm ran through a third-party application built on an underlying model, a companion bot platform, a wellness app, a chatbot embedded in a social network, the deploying entity is usually a proper co-defendant. The deployer typically controls the system prompt, the safety filter configuration, and the user-facing warnings. Those are precisely the design choices at the center of a defective product theory. In Garcia the deployer was the primary defendant, with Google reached as a component part manufacturer that supplied the underlying technology and the bespoke computing infrastructure. (order)

The upstream provider. Where a downstream developer builds on a foundation model through an interface, the provider is often reachable on a negligent entrustment theory: it knew the downstream product's user base and use case and licensed the model into an environment where the harms were foreseeable. That's the framing against Google in the Gemini matter.

Directors and officers. Where internal safety warnings are documented or plausibly alleged, officers who received them can be named on direct participation or aiding and abetting theories. Note the constraint: Smith & Wesson Brands v. Estados Unidos Mexicanos, decided June 5, 2025, holds that aiding and abetting ordinarily requires affirmative acts rather than omissions, and isn't satisfied by routine commercial activity that incidentally facilitates crime. Build the executive counts on decisions made, not on decisions withheld, wherever the record allows.

A drafting caution. Piling defendants into a caption without a discrete factual predicate for each is the most common pleading mistake in this docket. Plead a specific predicate for every named entity: the corporate role in the operating decisions, the officer's knowledge of the flagged conversations, the deployer's control over the safety filter. Motions to sever, motions to dismiss individual counts, and jurisdictional challenges land quickly on a complaint that reads as though the caption was assembled by pulling every arguable target into the file.

Plead around Section 230, and plead so you don't need to

Section 230 of the Communications Decency Act, 47 U.S.C. ยง 230(c)(1), immunizes an interactive computer service from being treated as the publisher or speaker of any information provided by another information content provider. Its application to chatbot output turns on a three-part test: the defendant is an interactive computer service, the cause of action treats it as a publisher or speaker, and the information came from another information content provider. (CRS LSB11097)

Plaintiffs attack the third prong. When a user sends a prompt, the model generates the response text and no third party supplies the words. The Congressional Research Service reports that Section 230 doesn't apply where a provider helped create or develop the content. (CRS PDF) The engine for that reading is the Ninth Circuit's decision in Fair Housing Council of San Fernando Valley v. Roommates.com, LLC, 521 F.3d 1157 (9th Cir. 2008) (en banc), holding that a service loses immunity when it materially contributes to the alleged unlawfulness. (opinion)

One district court has now ruled squarely. Bouck v. Meta Platforms, 2026 WL 810036 (N.D. Cal. Mar. 24, 2026), rejected Section 230 where the defendant used AI to generate advertising images and text, holding that degree of participation isn't protected. The plaintiffs lost on other grounds. Set against it is Patterson v. Meta, 2025 NY Slip Op 04447 (4th Dep't July 25, 2025), the Buffalo mass shooting case, which applied Section 230 to algorithmic arrangement of content and stated flatly that there's no strict products liability exception to the statute. (opinion) That's the split, and it isn't resolved.

Belt and brace: theories that survive if Section 230 applies

  • Product liability claims. The statute doesn't shield a defendant from claims based on its own conduct in designing a defective product. The Ninth Circuit's line of cases separating product defect from publishing claims is directly on point and worth reading in full before drafting.
  • Federal criminal hooks. Section 230(e)(1) doesn't immunize federal criminal law violations. Where a bombing or explosives matter implicates federal statutes, preserve those hooks.
  • Duty to warn. Failure-to-warn theories target the defendant's own communications, not third-party content, including what the developer said or failed to say to users about known safety limitations.
  • Anti-terrorism claims. In matters plausibly within 18 U.S.C. ยง 2333, preserve the statutory claim, analyzed under the Taamneh aiding and abetting standard, which Section 230 doesn't answer.
  • State consumer protection claims. Unfair competition and deceptive practices statutes reach the developer's own marketing and safety representations, and are less obviously reached by the statute than defamation-style claims. In Garcia the Florida deceptive practices count survived on allegations that bots held themselves out as real people and licensed therapists.

The current practice is to argue Section 230 doesn't apply and to plead theories that survive if it does. Note again what the defendants have actually done: mostly, they haven't raised it. Build accordingly.

The recharacterization that opens strict liability

The single most consequential pleading choice is recharacterizing the chatbot from an information service into a consumer product. That opens strict liability, design defect, failure to warn, and manufacturing defect theories, none of which require proof of specific intent or knowledge, only that the product was in a defective condition when it left the defendant's control and that the defect proximately caused the harm.

Joshi pleads strict products liability, defective design, negligent design, failure to warn, and negligent entrustment. (Law Commentary) Reporting confirms this is the dominant approach across the docket: most filed cases plead strict products liability, negligence, and wrongful death rather than treating chatbot output as user-generated content. (Bloomberg Law)

Judge Conway's May 21, 2025 order in Garcia is the high-water mark at the pleading stage. The court accepted, for purposes of the motion, that the application was a product, reasoning that the alleged defects, no age verification, no reporting mechanism, programmed human mannerisms, no self-harm intervention, are design choices severable from expressive content. The opinion is short and load-bearing. Read it alongside every complaint you draft in this space.

Know what stands against it. Winter v. G.P. Putnam's Sons, 938 F.2d 1033 (9th Cir. 1991), James v. Meow Media, Inc., 300 F.3d 683 (6th Cir. 2002), and Rodgers v. Christie (3d Cir. 2020) all hold that information, ideas, and expression aren't products. Meow Media put it directly: video game cartridges, movie cassettes, and internet transmissions aren't sufficiently tangible to be products in the sense of their communicative content. The plaintiff's answer is Garcia's severability reasoning, which puts the defect in the interface and the safety architecture rather than in the words.

Three sub-choices to make explicit in the pleading

Which theory of defect. Design defect and failure to warn are the workhorses. Manufacturing defect rarely fits, because a model's output isn't a batch that came off a line with a foreign object in it. Some plaintiffs are testing a state-of-the-art theory that treats the developer's own published safety specifications as the standard of care and pleads deviation from it.

What is the product. Be precise. In some framings it's the model weights, in others the deployed application, in others the safety filter configuration, in others the full stack. The choice determines which alternatives count as feasible for design defect purposes and which affirmative testing your experts have to build.

Which state's law. Choice of law here is unsettled and consequential. Florida applies Restatement (Second) principles. California applies its own regime with a consumer expectation test. State pleading differences can decide whether a claim survives a motion to dismiss, and the coordinated California proceeding means a California filing joins a record already in motion.

The framing isn't costless. Chapter 6 addresses the defense response: that generative AI is closer to a search engine or a bookstore than to a physical product, and that the product designation collapses once the First Amendment implications are taken seriously.

Foreseeability lives in the chat record and the moderation log

The specific allegations that make a complaint plausible under Iqbal and Twombly come from two places. Joshi is the model. The complaint alleges:

  • The chatbot advised on what type of gun to use and which ammunition went with which gun. (Fox 13)
  • The chatbot analyzed images the shooter uploaded, identified the firearms and ammunition, and told him his Glock was designed for quick use under stress. (CNN)
  • The chatbot discussed the busiest hours at the student union and the casualty level a mass shooting typically requires to attract national coverage. (Law Commentary)
  • The developer's own automated systems flagged comparable conversations in the parallel Canadian matter without escalation. (Al Jazeera)

Each allegation does distinct work. The first two supply the material assistance element that defeats a public availability defense. The third supplies foreseeability of a specific attack rather than generalized harm. The fourth supplies notice: the developer knew, or had constructive knowledge, that its models could and did generate these exchanges.

Two further moves are becoming standard. Plead the developer's own published warnings, meaning model cards, system cards, and red-team reports, as evidence it knew of the specific risk category. Then plead prior-incident notice: earlier lawsuits, media reports, and academic warnings that predated the deployment period. Together they convert "should have foreseen" into "in fact foresaw," which is much harder to defeat on a motion to dismiss.

California Senate Bill 53 has since made this easier. Frontier developers now publish annual safety frameworks and pre-deployment transparency reports summarizing catastrophic risk assessments and their results, and must report critical safety incidents to the state within fifteen days, or twenty-four hours where danger is imminent. Every one of those filings is discoverable foreseeability evidence, and the statute is generating a dated public record you can plead from directly.

Plead the interaction pattern, not the information

The July 2026 survivor complaints go further than Joshi on causation, asserting that without the assistance and participation of the chatbot, the shooter would have been unable to carry out the attack. (WCTV) That's a stronger but-for allegation than most product liability complaints require, and it invites the obvious counter: the shooter could have found the same information through open sources. The defense will press exactly that point.

The stronger framing isn't that the product supplied information. It's that the product supplied the interaction pattern that shaped and reinforced the intent. The Joshi complaint states it directly: the system remained engaged in the conversation, reinforced the shooter's perspective, expanded on it, and posed follow-up questions to maintain his involvement. (CNN) That's a claim about engagement design, not about information availability, and it maps cleanly onto product liability doctrine about foreseeable misuse of a designed feature.

Keep substantial factor causation in view as an alternative to but-for. In many states a plaintiff prevails by showing the product was a substantial factor in producing the harm even where independent factors contributed. That's friendlier terrain, and it fits the actual empirical claim: the product materially shaped an escalation that would have looked measurably different without it.

Superseding cause needs specific pleading attention. Every complaint has to anticipate the intervening criminal act defense and plead facts that make the third-party act foreseeable rather than superseding. In the shooting docket, the volume of the record and the alleged automated flagging do that work. In the suicide docket, the age of the user and the specificity of the escalation do it. In the weapons docket, the developer's own red-team documentation of the exact risk category does it.

The damages prayer and what it has to be built on

Joshi seeks compensatory and punitive damages in an unspecified amount for the widow and her two minor children. (Bloomberg Law) The July 2026 survivor complaints were the first in the docket to expressly seek punitives. Both include a jury demand.

Punitive damages require an allegation of malice, willfulness, or reckless disregard, which is why complaints in this docket work hard to establish that the developer knew of, or was on notice of, the specific risk and deployed anyway. The survivor complaints allege the product was rushed to market and that safety training was reduced, a pleading move aimed squarely at the reckless disregard standard.

The Raine guardrail-decay theory does double duty: it supports the design defect claim, because the product was defective by design at the time of harm, and it supports the punitive predicate, because removing a working countermeasure is conscious disregard. Look for a guardrail-change story in every intake and preserve the time-series evidence early. Second, where the defendant has a charitable or nonprofit structure, plead through to the operating entities that hold the assets and state the theory of substantive consolidation for damages purposes explicitly.

Pleading checklist

  1. Corporate structure sufficient to reach the operating entities that hold the assets, with a discrete factual predicate for each named entity.
  2. Executive-level knowledge or notice, where supportable, to preserve individual defendant claims and punitive exposure. Build it on affirmative decisions, not omissions.
  3. Detailed factual allegations from the chat record, characterized as operational planning in the shooting docket or coached self-harm in the suicide docket, rather than neutral information exchange.
  4. Allegations that the defendant's own moderation architecture flagged, or should have flagged, the interactions, with reference to published safety commitments and evaluation results.
  5. Strict product liability theories pleaded in the alternative to Section 230 arguments, with a precise identification of the product.
  6. A causation theory grounded in engagement design rather than information availability, pleaded under a substantial factor standard where state law allows.
  7. Explicit anticipation of the superseding cause defense, with a foreseeability record that supports foreseeability at the pleading stage.
  8. Punitive predicates, where supported, tied to specific pre-deployment safety warnings disregarded, guardrail decay, or contemporaneous internal knowledge of the risk category.
  9. State-specific choices on the product liability theory: consumer expectation against risk utility, the comparative fault regime, and any cap statutes, evaluated before filing.
  10. Preservation demands and litigation hold notices served on every named defendant contemporaneously with filing, covering chat logs, moderation records, and red-team reports.

Six drafting mistakes already on the record

  • Overreliance on Section 230. Some early complaints treated it as the whole case. It isn't, and defendants often aren't raising it. The complaint has to survive on product liability grounds whether or not a court reaches the immunity question.
  • Vague chat record allegations. "The chatbot provided information about weapons" isn't enough. Plead specific content, characterized as operational, with dates or date ranges. Joshi and Raine set the fidelity standard.
  • Missing corporate specificity. Naming a parent without pleading its operational role invites dismissal of that defendant.
  • Punitives without predicates. A punitive prayer with no underlying reckless disregard allegation reads as a placeholder. Build the predicate factually before the prayer arrives on the page.
  • Forfeiting the anti-terrorism claim. In matters plausibly within 18 U.S.C. ยง 2333, failing to plead the statutory claim gives up a valuable alternative theory. Preserve it, or record on the file why you elected not to.
  • Ignoring the deployer. Where a third-party integrator is involved, the deployer often made the specific design decisions at issue. Naming only the upstream provider leaves the more accountable defendant out of the case.
Back to top

Chapter 4

Evidence: chat logs, moderation records, and the discovery strategy

The proof in these cases sits in five places: the chat record, the developer's moderation and safety infrastructure, its pre-deployment safety documentation, law enforcement reconstructions, and the plaintiff's own comparative testing. Each has its own custody, authentication, and admissibility problem, and each supports a different part of the case.

The chat record is the case

The single most important artifact is the perpetrator's or decedent's conversation history. In Joshi that record is measured in the thousands of messages. In Raine it includes coaching conversations about method and note drafting spanning the months before the death. (complaint)

Custody is typically split five ways:

  • The defendant's servers, under retention policies that vary by product tier. Consumer accounts often retain for shorter periods than enterprise or programming-interface accounts, and the programming-interface path frequently logs differently than the consumer web interface.
  • The user's own devices, where cached copies, screenshots, downloaded transcripts, or browser history may survive. In suicide cases especially, device-level recovery is the family's earliest access to substantive content.
  • Cloud backups that may hold copies the user never intended to preserve.
  • Law enforcement, where records were seized under a warrant, subpoena, or preservation letter.
  • Third-party integrations, meaning browser extensions, note-taking applications, and interface wrappers that may have logged interactions the primary defendant can't control.

Assume some portion of the record will be public, and selectively public, before any court sees it. Reporters obtained the Florida State logs from the criminal case file and published their content in April 2026, more than a month before the civil complaint was filed. The Las Vegas department released a subset of the Cybertruck queries in a press release. (Las Vegas Metropolitan Police Department)

Write the requests to the product architecture, not to a generic chat log

Requests written in general terms produce productions in general terms. Ask for:

  1. The raw model input and output records, with timestamps and model version identifier for each turn.
  2. The moderation classifier scores associated with each turn, with the underlying rule identifiers.
  3. The system prompt or developer message that framed each session.
  4. The trace of any retrieval, tool call, or code execution that fed a response.
  5. The feature-flag or split-test assignment that determined which model behavior applied.
  6. Any account-level suspensions, warnings, or content flags, with the classifier scores behind them.
  7. Any exports the user made or attempted, with request logs.
  8. Cross-session identifiers, meaning device identifiers, network addresses, payment identifiers, and phone numbers, that link the account to related activity or other accounts.
  9. Product configuration data for the account: custom instructions, memory contents, tool authorizations, image and file uploads, voice interactions.

The moderation infrastructure the developer already admits exists

The Tumbler Ridge complaints allege the developer's automated systems flagged conversations in June 2025 in which the attacker described gun-violence scenarios. (Al Jazeera) Reporting adds that the account was suspended without notification to law enforcement. (Fortune) OpenAI's own statement in the Florida State matter confirms the architecture: "After learning of the incident, we identified an account believed to be associated with the suspect and proactively shared this information with law enforcement." (WCTV)

Those statements establish that a moderation system exists and that it produced actionable outputs. That's the foothold for discovery into:

  • The classifier or rule inventory for violent content, self-harm, weapons, and child sexual abuse material.
  • The thresholds at which flags trigger, and the escalation path from flag to human review to account action to law enforcement referral.
  • Historical logs of flags applied to the account at issue and to structurally similar accounts.
  • Change-management records for the moderation system in the period leading to the harm.
  • Staffing and headcount for the human review team, and any material change in review capacity or coverage.
  • The trust and safety escalation matrix and the written criteria for law enforcement referral, if any exist.
  • The document trail of decisions to relax, tighten, or reconfigure moderation thresholds during the relevant window.
  • The observability layer: internal dashboards, anomaly detectors, and reporting tools by which the safety team monitored real-world behavior. If a dashboard would have shown a spike in weapons-adjacent conversations in the account population, ask for it.

The Raine amended complaint's theory, that guardrails were relaxed before the harm, is the template for pleading this category. Discovery under that theory targets the time series of safety configuration: what changed, when, why, and who approved it.

Pre-deployment safety documents are the punitive predicate

Model cards, system cards, red-team reports, evaluation results, and internal risk assessments are discoverable and are the most likely route to punitive damages. The July 2026 survivor complaints target this category directly, alleging the product was rushed to market and safety training was reduced. (WCTV)

  • Model cards and system cards for every version deployed in the relevant period, including internal-only versions circulated before public release.
  • Red-team reports, particularly on violence, weapons, self-harm, and extremism. External engagements produce written deliverables; internal teams produce internal reports. Ask for both.
  • Internal risk assessments produced before launch, including release-readiness reviews.
  • Communications among senior leadership about known safety gaps, meaning the trail of messages and memoranda on which the release decision was made.
  • Contract and engagement records where third parties assessed safety, and the independent evaluators' own deliverables.
  • Board materials, safety committee minutes, and external advisor reports.
  • Employee complaints, resignations, and internal dissents about the safety of a release.
  • State transparency filings and incident reports made under California Senate Bill 53, which are dated, public, and specific.

The developer's own public disclosures are usually the pleading-stage foothold that makes the rest discoverable. Where a system card acknowledges the exact risk category in your case, that publication is foreseeability evidence on its face and comes in as an admission of a party opponent.

Parallel criminal records, and the rules that keep you out of them

The Florida criminal investigation is producing a parallel evidentiary record that will overlap substantially with civil discovery. (BBC) The subpoenas seek the developer's policies and training materials on threats of harm, its law enforcement cooperation procedures, and its public statements, reaching back to March 2024. British Columbia's anticipated action will produce another such record. The Las Vegas investigation produced a third.

Plan for four constraints:

  • Grand jury secrecy on federal criminal materials, which can't be transferred to civil counsel except under a specific court order.
  • Protective orders limiting dissemination of law-enforcement-obtained chat logs beyond the case in which they're produced.
  • Cross-border delay where a foreign investigation holds records relevant to an American civil matter, and mutual legal assistance procedures govern the transfer.
  • Sequencing. Take civil depositions after criminal proceedings where the alleged perpetrator's Fifth Amendment exposure would otherwise dominate the record.

The reverse flow is now routine: civil discovery produces documents that state attorneys general subpoena for their own investigations. Draft confidentiality provisions with that possibility explicitly in view.

Reproduction testing, and the trap inside it

Plaintiffs' experts attempt to reproduce harmful outputs on later versions, on comparable models, and on jailbroken variants. The Tumbler Ridge complaints allege the model evaded its internal filters to answer restricted prompts about lethal weaponry and the logistics of a violent attack. Reproduction work has to be:

  • Conducted under a written, reproducible protocol, with model version, temperature, system prompt, and prompt lineage documented for every trial.
  • Preserved as raw evidence, meaning screen recordings, interface logs, and exported transcripts, rather than as summaries.
  • Framed to answer specific factual questions relevant to the pleadings, not to produce shocking demonstrations that will be excluded under Rule 403.
  • Reviewed by ethics counsel where the testing itself may implicate the developer's terms of service or ordinary safety-research norms.

The published benchmark work now available is worth using as a comparator rather than reinventing. The CT-AI Benchmark tested 27 models against roughly 2,500 prompts under a documented protocol and reported that framing a request as research raised compliance from 17 percent to 42 percent. (CT-AI Benchmark) An expert who anchors reproduction work to a published protocol with a known error profile is in a much better position on cross than one who ran ad hoc trials.

Open-source availability benchmarks. The defense will offer evidence that the same information is readily available on the open web. Don't concede the empirical question. Counter on interaction quality: the tailoring to the user's context, the persistence across sessions, the reinforcement of stated intent. Public availability of a piece of information is not public availability of a coached, personalized, interactive plan. Chapter 6 covers the doctrinal architecture of that defense.

Retrospective analyses. Where a developer has published a post-incident analysis of a specific harm, that publication is an admission and often contains internal findings that would otherwise be protected as work product.

Authenticating text that changes every time you ask

Chat records are structurally unlike physical evidence.

  • Screenshot against interface export against server log. Each has a different admissibility posture. Server logs produced by the defendant under Rule 34 are strongest. Account exports are next. Screenshots without corroboration are weakest and should always be paired with a server-side or metadata-supported corroborant.
  • Model version drift. The same prompt yields different outputs across versions. This isn't a technicality, it's a first-order authentication problem. Every reproduction and every produced record must identify the model version, and preferably the exact checkpoint.
  • Account attribution. Connecting the account to the person when several people may have had access. A standard forensic problem, but uniquely important here, because the whole case turns on the identity of the user in the conversation.
  • Injection artifacts. Whether the record was shaped after the fact by custom instructions, memory features, or third-party wrappers. In products with persistent memory or user-configurable system prompts, the conversation you want to authenticate is the rendered conversation, while the underlying call may have been shaped by content the user never saw.
  • Multiparty rendering. Where a user pasted output into a messaging client, a document, or a note, the artifact recovered from the device may not be a faithful transcript. Corroborate against the server record wherever possible.

The best authentication package pairs three things: the defendant's server record, the user's device-level record, and a stipulated version-and-configuration statement fixing the model version and settings for each turn in dispute.

Preservation starts at intake, not at filing

Every matter begins with a preservation problem. Chat records are deleted or expire under product-tier retention rules. Model checkpoints are replaced on a rolling basis. Safety configurations change weekly. Serve the preservation demand at intake, and be specific:

  • The account's full conversation history in native format.
  • All server-side moderation logs and classifier scores for the account.
  • The exact model versions the account interacted with, including experimental variants.
  • The system prompts, developer messages, and tool configurations applied to the account.
  • The safety-configuration change log for the relevant period.
  • The internal messaging, email, and document repositories of the safety and trust and safety teams.

On the defense side the obligation is as heavy and less obvious. Once a matter is in reasonable anticipation of litigation, ordinary safety iteration, retiring checkpoints, collecting logs, rotating out red-team engagements, can produce inadvertent spoliation. A hold in this environment has to reach engineering, research, safety, and trust and safety simultaneously, and it has to cover model artifacts and system configurations, not only documents.

The remedies are unsettled. No published opinion has imposed a Rule 37(e) adverse-inference sanction on a generative AI developer. The machinery applies, and the plaintiffs' bar is prepared to test it.

Is model output a statement?

Hearsay. Federal Rule of Evidence 801(a) defines a statement as an oral assertion, written assertion, or nonverbal conduct of a person. A model isn't a person. The output is therefore either not hearsay at all, because it isn't a person's statement, or it's a business record or an admission of the party that operated the model. The plaintiff's position is usually that it's a party-opponent admission under Rule 801(d)(2), since it's the defendant's own product speaking. The defendant may argue it isn't a statement at all. Lay the foundation under both theories.

Best evidence. Where the claim depends on the exact wording of a turn, offer the server-side native record and treat printouts and screenshots as duplicates under Rule 1003. If only screenshots exist, pair them with authentication testimony from a witness who observed the interaction contemporaneously.

Two problems will mature as the docket does: expert authentication of output, meaning whether an expert may testify that a particular output is consistent with a named model at a named version, and reproducibility evidence offered as design defect proof.

Discovery checklist

Before the first responsive pleading, plaintiff's counsel should have:

  1. Served a preservation demand covering chat records, moderation logs, safety documentation, and internal safety communications.
  2. Engaged a digital forensics examiner to image the decedent's or perpetrator's devices.
  3. Identified every account identifier, meaning email, payment card, and phone, and every product and version the account interacted with.
  4. Made public records requests to law enforcement agencies with parallel investigations.
  5. Mapped the developer's public safety disclosures, meaning model cards, system cards, blog posts, testimony, and state transparency filings, for admissions to cite in the pleadings.
  6. Preserved contemporaneous news coverage showing what the developer said about safety in the period leading to the harm.
  7. Checked the coordinated California proceeding docket for discovery already taken on the same architecture.
Back to top

Chapter 5

Expert witnesses in AI liability cases

Expert testimony carries more weight here than in most product liability matters. A jury can't be expected to work out on its own how a large language model produces an answer, why a specific output appeared, whether it was reasonably preventable, or what a safer alternative design would have looked like.

A good expert does more than display his or her own knowledge. The job is to teach the jury enough about the mechanism that the jurors reach the same conclusion on their own, behind closed doors.

The roster, and what each discipline is for

Plaintiff-side expert disciplines
DisciplineWhat it establishesRetain whenMain exposure
Safety engineering and human factorsForeseeable misuse, hierarchy of controls, warning adequacy, field action thresholdsBefore the first discovery requestNot a machine learning specialist
Machine learning systemsHow the model was built, why it produced the output, what alternatives were feasibleBefore the complaint is filedNovel methodology
Digital forensicsAuthentication of the record, account attribution, reproducibilityAt intakeModel artifact work is a new specialty
Threat assessmentPre-attack warning behaviors and their detectabilityOnce the chat record is in handFit to the specific record
Clinical or forensic psychiatryInteraction between the underlying condition and the engagement patternOnce the chat record is in handCausation against a pre-existing trajectory
Regulatory and industry standardState of the art and the developer's own commitmentsAfter the safety documents are producedStandards without force of law
Warnings and communicationsAdequacy of user-facing safety representationsIn failure-to-warn mattersOverlap with safety engineering
Forensic economicsLost earnings, household services, hedonic measuresBefore the damages phaseAssumptions about an unlived life

You don't need every discipline in every case. A minimum viable panel in a mass shooting matter is safety engineering, machine learning systems, digital forensics, threat assessment, forensic economics, and regulatory standards. In a suicide matter, substitute forensic psychiatry for threat assessment. In a bombing or weapons matter, add the relevant domain scientist.

Daubert exposure in a field with no settled methodology

Every category faces challenge under Daubert v. Merrell Dow Pharmaceuticals, 509 U.S. 579 (1993), and Kumho Tire Co. v. Carmichael, 526 U.S. 137 (1999), as codified in Federal Rule of Evidence 702 and mirrored in most state regimes. Two challenges are close to certain.

Peer-reviewed methodology. AI safety is a young field. The methods an expert uses to analyze a model's safety properties may not carry the settled peer-reviewed status Rule 702 prefers. Anchor the methodology to established parent fields, meaning safety engineering, human factors, and the statistical analysis of classifier performance, and cite peer-reviewed work in those parent fields. Relying only on non-peer-reviewed AI safety literature, however well regarded the source lab, invites a challenge you'll lose.

Fit to the case. A well-credentialed researcher still faces a fit challenge if the opinion depends on inferences the record doesn't support. Map every stated opinion to specific record facts. A general opinion that large language models pose safety risks isn't testimony. A specific opinion that the deployed model's moderation configuration in the relevant window wouldn't have flagged a named conversation because a named classifier's precision on a named category fell below a stated threshold is testimony.

Three second-order attacks now emerging

The novel science attack. Defense counsel will argue the expert is offering a new methodology under an old label, safety engineering, and demand a full hearing on the reliability of that methodology as applied to AI systems.

The not-a-systems-expert attack. Defense counsel will argue a safety engineer without deep machine learning training can't competently opine on model behavior. The remedy is role partitioning: the safety engineer speaks to the design defect framework, the systems expert speaks to the mechanics, and the two testify in coordinated but non-overlapping registers.

The no-comparator attack. Defense counsel will argue there's no accepted safer alternative design the expert can point to, so the design defect claim fails at the reasonable-alternative-design threshold. Be ready with the developer's own published safety commitments and with specific technical alternatives that were feasible in the relevant window: higher-precision classifiers, human-in-the-loop escalation, cross-session escalation, account-level throttling, and delayed responses on flagged queries.

The safety engineer translates the case into doctrine the jury already knows

Safety engineering is a mature discipline with decades of case law and industry standards behind it. Applying it to a generative system requires familiarity with how the model actually behaves, but the analytic framework travels well from other product domains. That's why the practitioner community has begun retaining safety engineers from adjacent fields, meaning pyrotechnics, firearms, incendiary devices, and amusement park safety, rather than waiting for a dedicated AI safety expert market to mature.

The qualified safety engineer asks the same five questions asked in any product case.

  1. What is the intended use, and what are the reasonably foreseeable misuses? For a general-purpose chatbot, the foreseeable misuse envelope includes weapons research, self-harm planning, and impersonation. The developer's own model card, published before deployment, usually documents that it foresaw exactly these.
  2. What hierarchy of controls is actually in place? Elimination, meaning the product doesn't offer the functionality, and substitution, meaning queries route to a safer path, are stronger than engineering controls such as classifiers and refusal filters, which are stronger than administrative controls such as usage policies and warnings. Document which controls the developer chose and why higher-tier alternatives were feasible and not selected.
  3. What warnings accompany the product, and are they adequate to the foreseeable use? The American National Standards Institute Z535 series supplies the framework: hazard identification, consequence, avoidance. A terms-of-service acknowledgment isn't a compliant warning. A use-case-specific in-product warning is.
  4. What are the recall or field-action criteria? In consumer products, a design defect known to cause serious harm triggers recall, redesign, or field notice. Ask whether the developer's response to prior harms matched what the safety literature calls an adequate field action.
  5. What does the incident record show? Every mature product safety program keeps a complaint and incident database. Discovery of that database, and of the analytics run against it, is central.

The safety engineer's job isn't to teach the jury artificial intelligence. It's to teach the jury that the standards for safe product design that governed prior generations of technology apply here too, and that this defendant either met them or didn't.

The systems expert makes the model's behavior intelligible

Explain the mechanics. How the model was trained, meaning pretraining, supervised fine-tuning, and reinforcement learning from human feedback; how safety training works; how classifiers layered on top of the model function; how system prompts and developer messages shape output; how memory and tools change the interaction. Deliver it at a level a lay jury follows, usually with visual aids, without extraneous technical detail that draws sustained objections.

Analyze the record. Read the chat logs and moderation records with technical fluency: what the classifier scores indicate, why particular refusals fired or didn't, what the timing and sequence of turns implies about model state and configuration.

Speak to feasibility. Testify to alternative designs that were feasible in the relevant window. This is the technical heart of the design defect case.

The best expert in this category has an academic or industrial research background that will withstand a Rule 702 challenge, hands-on familiarity with modern large-model systems, and enough communication skill to make the technical content vivid without hyperbole. Retaining a nameplate academic who can't testify persuasively to a jury is a common and expensive mistake.

Digital forensics, where three things differ from the ordinary matter

Server against device. Where the primary record is server-side, the examiner authenticates against export formats, timestamp fidelity, and metadata completeness rather than against imaged hardware. Where the primary record is device-side, standard examination applies with an added layer for client caching behavior.

Model artifacts. The examiner may need to authenticate checkpoints, configuration files, and system prompts produced in discovery. This is a young specialty. Retain examiners who have specifically done model artifact work.

Reproducibility. Where the expert testifies to reproduction attempts, the forensic discipline of reproducibility, meaning chain of custody, environmental documentation, and deterministic replay, becomes central. Reproduction evidence a third party can't reproduce is rarely worth offering.

Threat assessment maps the record against the pathway to violence

Did the perpetrator exhibit pre-attack warning behaviors? The pathway-to-violence literature identifies recognizable markers: grievance, ideation, research, planning, preparation, breach, attack. The expert maps the chat record against them.

Were those markers detectable to a reasonably designed moderation system? This is the design defect analog for behavioral evidence. The expert testifies to what a classifier or human reviewer could have seen if the architecture had been configured to look for pathway markers rather than only for narrow policy-violation categories.

Retain this expert early and keep the work coordinated with the systems expert, who supplies the technical capability analysis, and the safety engineer, who supplies the design defect framework.

Psychiatry carries the hardest causation opinion in the docket

In suicide, self-harm, and delusion cases, the psychiatric expert addresses whether the model's engagement pattern changed the outcome for a user with an underlying condition. That's the battleground in Raine, Garcia, and the Greenwich matters.

Two literatures anchor the testimony: the general psychiatric literature on suicide risk assessment, and the emerging literature on human and machine interaction effects, parasocial attachment to chatbots, and delusional reinforcement. The expert has to cite both, connect them to the specific record, and withstand a cross built entirely on the underlying condition.

Where the decedent had a documented psychiatric history, the opinion usually takes the form of a substantial contribution analysis: the condition established a trajectory, and the engagement pattern accelerated it, closed off protective factors, or supplied content the trajectory alone wouldn't have produced. That supports substantial factor causation without requiring the expert to claim, implausibly, that the outcome would have been prevented in a world without the model. Discarding the stronger claim you can't support is fundamental to credibility, and credibility is the expert's whole currency.

The regulatory expert supplies the standard of care

  • The National Institute of Standards and Technology AI Risk Management Framework version 1.0, January 2023, and its Generative AI Profile, July 2024. The federal baseline documents on responsible development and deployment.
  • ISO/IEC 42001, the artificial intelligence management system standard, published 2023.
  • The European Union Artificial Intelligence Act, Regulation (EU) 2024/1689, with its risk-tier framework and its obligations for general-purpose models.
  • The Institute of Electrical and Electronics Engineers 7000 series on ethics-by-design.
  • The July 2023 voluntary White House commitments signed by the leading developers, and the developer-specific safety commitments published since.
  • Frontier Model Forum publications and the developer coalition's stated commitments.
  • California Senate Bill 53 filings, meaning the published frontier frameworks, transparency reports, and incident reports, which are dated and specific to the model version at issue.
  • The developer's own public statements in blog posts, model cards, system cards, congressional testimony, and interviews. These serve as standard-of-care evidence and as admissions.

The expert testifies to what a reasonably prudent developer committed to doing in the relevant window, and how this defendant's conduct compared to those commitments and to the industry standard the documents reflect.

What the defense panel looks like

  • First Amendment and information policy experts on whether the outputs are protected speech and whether restricting them would offend the First Amendment or its state analogs.
  • Comparative availability experts demonstrating that the same information is broadly accessible on the open web, in reference works, and in ordinary search results. This is the empirical foundation of the no-material-contribution defense.
  • Alternative cause experts, clinical, criminological, or social, offering superseding cause accounts. In shooting matters that usually means a criminologist on the correlates of the attack pattern. In suicide matters, a psychiatrist on the underlying condition.
  • Defense systems experts testifying that the design met contemporary industry standards, that the plaintiff's proposed alternatives weren't technically feasible at the time, and that the outputs were consistent with a good-faith safety configuration.
  • Damages experts challenging lost earnings, life expectancy, and any enterprise-value framing.

The defense panel is typically deeper on the technical question and shallower on the safety engineering framework. Be ready for that asymmetry, and don't concede the technical ground because the other side's experts arrived with more famous credentials.

Seven things to prepare before the deposition

  1. Model versioning. Any opinion about what the model would have done must specify a version, a system prompt, and a set of settings. The witness should be able to say on the record exactly which version and configuration each opinion depends on.
  2. Prompt sensitivity. Small changes in phrasing produce large changes in output. The expert should explain how the reproduction controlled for prompt variability, and distinguish "the model would produce this in these conditions" from "the model always produces this."
  3. Non-determinism. Most deployed models produce non-deterministic output at typical settings. The expert must explain sampling temperature, the top-k and top-p sampling methods, and seed effects without losing the jury. Where the configuration is deterministic, meaning temperature zero with a fixed seed, say so and explain what that means for reproducibility.
  4. The model against the deployed product. Cross will try to blur them. Distinguish the underlying model weights, the deployed application with its system prompt and interface, the account configuration with its memory and custom instructions, and the specific session with its in-context state. Only the second and later categories are properly called the product for design defect purposes.
  5. Safety training against moderation. These are different things. Safety training modifies behavior at the weights level. Moderation adds a filter layer inspecting inputs and outputs at the time of use. Confusing them on the record invites impeachment.
  6. The publicly available information cross. The disciplined answer: the information may have been available, but the coached, personalized, sequenced interaction was not. Public availability of a fact and public availability of a plan are different things.
  7. The jailbreak cross. Where reproduction relied on any non-standard prompting, the defense will attack it as unrepresentative. The expert should be able to explain why the reproduction is nevertheless probative, and point to record evidence that the user produced comparable outputs without a comparable technique.

Expert retention checklist

  1. Retain the systems expert and the digital forensics examiner before the complaint is filed. Their input shapes the pleading.
  2. Retain the safety engineer before the first discovery request goes out. Their input shapes the requests.
  3. Retain the psychiatric and threat assessment experts after the chat record is in hand and before the deposition of the developer's safety leadership.
  4. Keep the panel non-overlapping in stated opinions. Two plaintiff experts contradicting each other on model architecture is a gift to the defense.
  5. Budget for testing, meaning output reproduction, classifier analysis, and secondary forensic work, and authorize it in the retention letter.
  6. Confirm each expert's methodology is anchored to a peer-reviewed parent field before the report is written, not after the challenge is filed.
Back to top

Chapter 6

Defenses: Section 230, the First Amendment, and proximate cause

The defenses fall into four families: Section 230 immunity, First Amendment protection of model output, proximate cause including the intervening criminal act, and a group of secondary defenses that matter in specific matters but rarely decide a case alone.

Every defense case presents them in combination, and each one gains weight as the others weaken.

Section 230, the defense that mostly isn't being pleaded

Section 230(c)(1) states that no provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider. The carve-outs in subsection (e) preserve federal criminal law, intellectual property law, communications privacy law, and sex trafficking claims. Roommates.com added the material contribution gloss: a platform loses immunity for content whose unlawfulness it materially contributed to. (opinion)

Start with the practical fact. In the AI harm cases actually filed, defendants have largely declined to plead the immunity. Character Technologies didn't raise it in its motion to dismiss in Garcia, and Judge Conway's order contains no immunity analysis. OpenAI didn't raise it in Walters. The reason is strategic: pleading Section 230 concedes that the output is somebody else's content, which sits awkwardly beside the argument that the output is the platform's own protected expression.

The positions, when it is pleaded

Defense. The output is a compilation, summary, or synthesis of third-party training content, and so remains information provided by another at one remove. Outputs drawn from retrieval over public web content are straightforwardly third-party content. Even where the model generates novel text, the statute's protective purpose is fully engaged. And the claim, however it's labeled, is functionally about the content of the model's speech, which is what the statute was written to preclude.

Plaintiff. The text focuses on content provided by another, not on whether content is derivative. When the model composes the reply, the platform provides the content. Product liability claims aren't publisher-or-speaker claims; they target the design of the product. Subsection (e)(1) carves out federal criminal law, which is directly implicated in bombing and explosives matters. And if model output is the platform's own speech for First Amendment purposes, it can't simultaneously be third-party content for immunity purposes.

Where the courts actually are

No appellate court has ruled squarely on the immunity's application to generative output. Below that level there's a genuine split on the adjacent question.

  • Bouck v. Meta Platforms, 2026 WL 810036 (N.D. Cal. Mar. 24, 2026), rejected the immunity where the defendant used AI to generate advertising images and text. The only ruling squarely on generative output.
  • Anderson v. TikTok, No. 22-3061 (3d Cir. Aug. 27, 2024), held that algorithmic recommendation is the platform's own first-party expressive product under Moody, so the immunity doesn't apply.
  • Patterson v. Meta, 2025 NY Slip Op 04447 (4th Dep't July 25, 2025), expressly disagreed with Anderson, applied the immunity to algorithmic arrangement of third-party content, and held there's no strict products liability exception to Section 230. (opinion)
  • In re Social Media Adolescent Addiction, No. 4:22-md-03047 (N.D. Cal. Nov. 14, 2023), rejected an all-or-nothing approach and analyzed defect by defect. Not barred: parental controls, age verification, account-deletion barriers, appearance filters, reporting mechanisms, default session limits. Barred: endless feed, engagement-optimized ranking, ephemeral content, and notification clustering of third-party content.

The defect-by-defect approach is the one to build toward. It's the reason a well-pled complaint identifies the product as the safety architecture and the interface rather than as the words.

Practice note for both sides. Treat the immunity as an issue preserved for appellate resolution, not as a threshold defense that resolves the case. Plaintiffs plead around it. Defendants preserve it. Neither side should stake a case on it.

Whether model output is speech at all

The defense case. The First Amendment protects a wide range of expression, including expression about dangerous activities. Books that discuss explosives, films that depict violence, and encyclopedias that describe weapons are protected, subject to narrow exceptions. Under Moody v. NetChoice, 603 U.S. 707 (2024), algorithmic curation choices are protected expression, and the model's generative choices, its selection and combination of words in response to a prompt, are the platform's own protected expression. Brown v. Entertainment Merchants Association, 564 U.S. 786 (2011), holds that interactivity is a matter of degree rather than kind and doesn't strip protection from an expressive work.

The plaintiff case. Speech integral to criminal conduct, true threats, incitement, and speech providing material support to specific criminal acts isn't fully protected. Rice v. Paladin Enterprises, 128 F.3d 233 (4th Cir. 1997), the murder-manual case, is the closest analogue: the Fourth Circuit held that the publisher of a how-to-commit-murder manual could be sued in tort by the victims' families notwithstanding the First Amendment, because the material was the vehicle of the crime itself. (opinion)

Read Rice carefully before relying on it. The holding rested on a stipulation that the publisher intended and knew the book would be used by criminals to plan and execute murder for hire, and that it assisted the specific killer. Nothing in the chatbot docket comes with that stipulation. The plaintiff's task is to build its equivalent out of system cards, red-team reports, moderation flags, and internal communications. That's the real work of the foreseeability chapter, and it's why the discovery in Chapter 4 matters more than any argument in this one.

Know the other side of the media lineage too. James v. Meow Media, Inc., 300 F.3d 683 (6th Cir. 2002), applied Brandenburg v. Ohio and rejected liability against video game and film defendants after a school shooting, on three grounds: no intent to incite, a desensitization theory that lacked imminence, and the gap between millions of users and a handful of killers. That last point, the denominator, is the defense's most durable argument in this docket and shouldn't be answered by ignoring it.

Two features that distinguish the AI case from the printed manual

  1. The output is personalized to the user's specific situation in a way a printed book can't be. That personalization is the essence of the material assistance element.
  2. The output is generated in real-time interactive dialogue, and the interactivity is a design feature of the product rather than a species of the speech. Product liability claims about interactive design have historically not been treated as First Amendment matters.

Judge Conway declined to accept the First Amendment defense at the pleading stage in Garcia, applying an expressive-conduct framing and relying on Justice Barrett's concurrence in Moody to question whether autonomously generated output reflects human expressive choice. That ruling binds no other court and has drawn substantial criticism, including the argument that Barrett was addressing curation and moderation rather than newly generated speech. Treat it as a template plaintiffs are working from, not as settled law.

Watch the state analogs. Several state supreme courts read their own speech clauses more broadly than the federal First Amendment. Filing in a jurisdiction with a strong state clause changes the constitutional analysis and, in some matters, the venue calculation.

Superseding cause is the strongest defense in the docket

The most powerful defense is the old rule that a third party's intentional criminal act is generally a superseding cause that breaks the chain of proximate causation. Defense counsel will press the perpetrator's independent criminal decision, the availability of the same information from open sources, the absence of any specific threat communicated to the defendant, and the absence of any pre-attack contact between the defendant and law enforcement or the eventual victims.

Superseding cause isn't a mechanical rule. Restatement (Second) of Torts ยง 442 lists the factors that make an intervening act superseding, and the Third Restatement preserves the framework. Foreseeability of the general kind of harm is dispositive in most jurisdictions. A foreseeable criminal act isn't superseding. An unforeseeable one is.

Both readings have recent support. Patterson held the Buffalo shooter's intervening criminal acts broke the causal chain, with Justice Nowak dissenting that proximate cause is a jury question. California's pattern instruction on the point tracks Restatement ยง 448 and preserves liability where the defendant created a situation that facilitated the crime. Meow Media went the other way, calling the shooter's reaction too idiosyncratic to have been anticipated.

The four moves plaintiffs use to get around it

  1. Category foreseeability. The developer publicly acknowledged the risk category, meaning weapons research or self-harm coaching, in its own model card. That publication proves foreseeability of the category of harm.
  2. User-specific foreseeability. The developer's own automated moderation flagged this user's conversations, or structurally similar ones, before the harm. That proves foreseeability of harm to this user or one like him.
  3. Design defect reframing. Even where the criminal act would otherwise supersede, a defective product that facilitates the act is a separate proximate cause. Soto v. Bushmaster Firearms, 331 Conn. 53 (2019), is the template from the firearms line: wrongful marketing claims survived the federal immunity statute on the theory that the advertising modeled and encouraged the misuse. (opinion)
  4. Negligent entrustment. Where the developer entrusted a dangerous instrumentality to a foreseeably dangerous user, the criminal act isn't superseding; it's the exact harm the doctrine exists to reach.

Be honest about the fourth. Soto is also where negligent entrustment failed. The Connecticut court held the doctrine requires the direct recipient's individual unfitness, not class-based foreseeability, and refused to extend it to foreseeable misuse by someone other than the entrustee. That's the obstacle in front of every negligent entrustment count in this docket. The answer, where the record supports it, is the flagged account: a documented, account-specific signal converts a class-based argument into an individualized-knowledge argument, which is the form the doctrine actually accepts.

The duty to warn a third party is the argument that's coming

The Las Vegas matter produced the first serious public argument that a general-purpose conversational agent owes a duty to alert law enforcement when it receives operational planning queries about a specific violent act. (New York Times) The Tumbler Ridge facts, meaning a flagged account, an internal recommendation to notify police, and a decision not to, are the paradigm test case.

The obstacles are real. There's no therapist-patient special relationship of the kind Tarasoff v. Regents of the University of California rests on. Violence prediction is unreliable even for trained professionals. The scale is millions of users rather than dozens of patients. And a reporting duty carries surveillance and false-positive costs the courts will weigh. The scholarly proposal that has the most traction frames it as a narrow negligence duty of human oversight, meaning restricting access or alerting authorities when a system's own automated flag fires, rather than as strict product liability.

Note the tension with Smith & Wesson Brands v. Estados Unidos Mexicanos, decided June 5, 2025, which holds that aiding and abetting ordinarily requires affirmative acts rather than omissions. A theory built on a failure to report is an omission theory. It has to run in negligence, not in aiding and abetting, and the pleading should say so.

Comparative fault, arbitration, and the rest

Comparative fault of the perpetrator. Where the perpetrator is a co-defendant, allocation is a first-order issue, and in most states the intentional criminal act draws the largest share. Whether the developer is jointly liable or only severally liable in proportion to its own fault is a state-law question with substantial damages consequences. Evaluate the joint-and-several rules at intake.

Comparative fault of the decedent. In suicide matters the defense will argue the decedent's own actions belong in the allocation. Availability varies widely by state, and some states bar comparative reductions in suicide cases where the decedent had a diagnosed condition affecting judgment.

Assumption of risk. The defense will invoke the terms of service, the model card's published warnings, and in-product disclosures. Assumption of risk in product cases typically requires specific knowledge of the risk and voluntary acceptance. A boilerplate click-through is unlikely to satisfy either element in most jurisdictions. Don't concede it.

Preemption. No federal statute currently preempts the state-law product liability claims in this docket. Monitor congressional developments, covered in Chapter 8, without treating preemption as a near-term threat. Note that California Senate Bill 53 provides for enforcement by the state attorney general and no private right of action, while Senate Bill 243 does create one, with statutory damages of at least one thousand dollars, injunctive relief, and fees.

Statute of limitations. Wrongful death statutes typically run two to three years from death. Discovery-rule tolling may be available where the plaintiff first learned of the developer's role afterward, through media coverage, a criminal disclosure, or an attorney general announcement. Document the analysis at intake and reflect it in the complaint.

Personal jurisdiction. Developer defendants will challenge jurisdiction outside their principal place of business. Be ready with targeted marketing in the forum, revenue from forum users, and in-forum harm.

Arbitration. Where the terms include an arbitration clause, the defense will move to compel. In matters involving minors, non-signatory family members, or wrongful death claims by non-user plaintiffs, there are substantial arguments against enforceability. In Raine and Garcia, arbitration wasn't the barrier the defense might have wanted.

Abstention and parallel proceedings. Where a state and a federal action arise from the same incident, expect a motion to dismiss or stay under Colorado River. It failed in Lyons on April 13, 2026, on the ground that the two actions weren't necessarily coextensive. (Courthouse News)

The defense narrative, as already telegraphed

OpenAI's public statements preview it: the model provides factual responses to questions with information that could be found broadly across public sources on the internet, and it didn't encourage or promote illegal or harmful activity. (Reuters) Expect the defense to lean on:

  1. Comparative availability evidence, with substantial expert work on what the model added over open sources.
  2. Absence of specific-threat notice, meaning no targeted communication identifying the perpetrator and the victim.
  3. First Amendment framing of the outputs, preserved throughout and argued in the alternative.
  4. Section 230 arguments preserved for appeal even where not adopted below.
  5. Superseding cause grounded in the perpetrator's independent decision and psychiatric or ideological trajectory.
  6. Aggressive Rule 702 practice against the systems, safety engineering, and threat assessment experts.
  7. A state-of-the-art defense that the developer met the industry standard at the time. This one cuts both ways, because it opens the door to the plaintiff's regulatory expert on what the standard actually was, but the defense will run it hard wherever the developer can claim to have led rather than lagged.
  8. The denominator argument, meaning the ratio of millions of ordinary users to a handful of catastrophic outcomes. The Rinderknecht jury shows it lands.

Answering the publicly available information defense

Reframe from information to plan. The model didn't retrieve a fact. It synthesized a plan personalized to the user's stated intent.

Reframe from single output to sustained interaction. The case isn't about one turn. It's about a pattern of engagement over weeks or months.

Reframe from availability to accessibility. Information that exists somewhere on the open web isn't the same as information a general-purpose chatbot will deliver on demand to a user with no technical skill and no research effort. The published benchmark work quantifies the gap: roughly a third of tested responses gave usable uplift over a web search. (CT-AI Benchmark)

Point to the developer's own commitments. The model card usually documents that this category of information was flagged as a risk and that safety measures were meant to prevent its production. That's the developer's own concession that the information wasn't merely public.

The defenses interlock, and both sides should plan for the full stack

A weakened Section 230 posture makes the First Amendment defense more important. A weakened First Amendment defense makes proximate cause more important. A weakened proximate cause defense makes comparative fault and damages the last line. No single defense is case-dispositive in the current state of the law, and building a record for only one of them is how a case gets lost on the other three.

Back to top

Chapter 7

Damages, punitives, and personal liability

Damages sort into three tiers: ordinary compensatory recovery under the forum state's wrongful death and personal injury measures, punitive exposure predicated on reckless disregard or worse, and, in the most aggressive filings, personal liability of the developer's executives. Coverage sits underneath all three and will drive settlement.

One number anchors the field so far. On March 25, 2026 a Los Angeles jury in the coordinated social media proceeding found Meta and Google negligent in design and awarded three million dollars compensatory and three million punitive. The court had rejected strict products liability and sent the case to the jury on negligence. It's the only completed verdict on the design of engagement technology, and every valuation in this docket starts from it until an AI verdict replaces it.

Compensatory measures, and four issues specific to this docket

Standard measures apply: economic loss, meaning lost earnings, lost household services, and medical and funeral expenses; non-economic loss, meaning pain, suffering, loss of consortium, and loss of parental care; and in some jurisdictions hedonic damages for loss of enjoyment of life. In most respects the calculation looks like any comparable product case.

Multi-victim scaling. Mass shooting matters generate parallel plaintiffs whose damages will be tried separately or in coordinated proceedings. The Tumbler Ridge docket includes seven complaints. The Florida State docket includes at least four. Evaluate coordination early, and understand that the first plaintiff to reach a verdict sets the anchor for every later matter against the same defendant.

Aggregation across matters. As parallel matters proceed, discovery developed in one becomes usable in others. Common-interest agreements among plaintiffs' counsel accelerate the shared work, and defendants will increasingly seek protective orders limiting cross-matter use. Negotiate that language at the outset of each matter, not after the first production.

Emotional distress claims by non-decedent plaintiffs. In suicide cases, siblings, parents, and in some states other close relatives may hold negligent infliction claims distinct from the wrongful death recovery. The bystander rules vary by jurisdiction. Plead them where they exist.

Lost future earnings in child cases. Where the decedent was a minor, the lost-earnings component rests on assumptions about a career that never happened. The economist has to defend those assumptions on cross, and the damages case has to be ready for the unknowable-future attack.

Enterprise value. Some plaintiffs have begun referencing the developer's enterprise value in describing the magnitude of the harm. Admissibility turns on state punitive law and on constitutional review under State Farm v. Campbell and BMW v. Gore. Treat enterprise value as a punitive issue, not a compensatory one, and don't blur the two in front of the jury.

Punitive predicates come from the developer's own files

The July 2026 survivor complaints were the first in the docket to seek punitives expressly. (WCTV) The predicates now in use:

  • Allegations that the product was rushed to market and safety training was reduced.
  • Internal red-team reports identifying the risks that later materialized.
  • Safety-team departures or reorganizations preceding the deployment at issue.
  • Competitive pressure influencing the release schedule.
  • Guardrail relaxation of the Raine type, meaning the developer loosened safety configurations in the period before the harm. (Washington Post)
  • Public misrepresentation of the model's safety properties, actionable as a freestanding consumer protection claim and as evidence of conscious disregard.
  • An internal recommendation to notify law enforcement that leadership declined to follow, which is the Tumbler Ridge allegation and the strongest punitive fact yet pleaded in the docket.

The standard. State law typically requires willful and wanton conduct, reckless disregard, malice, or gross negligence depending on the jurisdiction. The federal constitutional overlay of State Farm, Gore, and Philip Morris constrains the ratio of punitive to compensatory damages and forbids punishment for harm to non-parties. Expect substantial post-verdict litigation over any award, under both state remittitur rules and federal review.

Guardrail decay as the classic predicate. The theory converts an ordinary product case into a conscious-disregard case: the developer knew of the risk, evidenced by the prior guardrail; had a working countermeasure, evidenced by that guardrail's prior existence; and removed it. Knew, could have prevented, chose not to. That arc is the punitive predicate in its textbook form, and it's why the time-series evidence in Chapter 4 matters so much.

Where the documents live. Three repositories: the safety team's internal messaging, email, and document channels; the release-readiness review materials for the version at issue; and board and senior-leadership communications about safety. Target all three, and pair the requests with corporate-representative depositions of the people who made the release decision.

Bifurcation. Some jurisdictions try punitives in a separate phase after liability and compensatory damages. Bifurcation shapes discovery, expert testimony, and settlement. Assess the forum's practice before the pretrial order is filed.

Naming the chief executive, and what it actually buys

Joshi names corporate entities and the shooter. The Tumbler Ridge and July 2026 survivor complaints name Sam Altman personally. (Mother Jones; WCTV) Individual naming is doctrinally viable where the executive personally participated in the decision that produced the harm.

Direct participation. Where an officer personally participated in the tortious conduct, meaning approving a release known to be unsafe, overruling internal safety objections, or directing a guardrail relaxation, direct liability lies with no piercing analysis required. This is the strongest ground and the one that survives Smith & Wesson, because it rests on affirmative acts.

Aiding and abetting. Available in some jurisdictions where an executive knowingly assists tortious conduct, but now constrained: the Supreme Court's June 2025 decision requires conscious and culpable participation in a specific wrong, ordinarily through affirmative acts, and treats routine commercial activity that incidentally facilitates crime as insufficient.

Fraudulent misrepresentation. Executives who make public statements about safety they know or should know to be false can be personally liable. In a field where chief executives testify to Congress and publish safety commitments, this predicate has more traction than it does in most industries.

Veil piercing. Where the corporate form has been used to defeat legitimate claims. A hard predicate and rarely dispositive.

What naming buys beyond assets. Discovery access to the executive's own communications. Deposition access to a witness whose corporate testimony would otherwise be confined to noticed topics. Settlement leverage against a corporate defendant that doesn't want its chief executive tied up in litigation. And, in some matters, media leverage that shapes settlement.

The care it requires. Naming an executive is a serious pleading move and needs a specific factual predicate. A caption decoration with no foundation is both an ethical exposure and a strategic mistake, and it gives the defense an easy early win that costs the rest of the complaint credibility with the judge.

Coverage will drive settlement more than doctrine will

The insurance landscape for these claims is unsettled and will shape settlement substantially over the next several filing cycles. The questions:

  • Directors and officers coverage for individual-defendant claims, including the bodily injury, intentional acts, and insured-versus-insured exclusions.
  • Commercial general liability coverage for the corporate defendant, particularly the exclusion analysis for bodily injury arising out of professional services or electronic content.
  • Cyber liability coverage for chatbot outputs, where the standard policy forms were written before generative systems existed.
  • Errors and omissions coverage where the developer offers the model as a service to downstream developers.
  • Reinsurance response, particularly aggregate limits and per-occurrence definitions in mass-harm scenarios.

Rating agencies have begun publishing analyses of the exposure. (Moody's) Coverage litigation is already appearing alongside the underlying tort suits and will accelerate as insurers seek declaratory judgments.

What to do about it. Identify the developer's insurers and coverage structure at intake. Limits, exclusions, and reservation-of-rights letters are discoverable and are central to realistic settlement modeling. On the defense side, coordinate with coverage counsel from the outset, particularly on notice and cooperation.

Structured settlement, and the two things that will complicate it

As the docket matures, expect the aggregate structures common to other mass torts: matrix settlements, opt-in claim procedures, and independent claims administrators. The economics point that way, because parallel plaintiffs, common defect theories, and a small number of defendants make individualized trials expensive for everyone. The January 2026 resolution of Garcia and four related cases on confidential terms is the first data point.

Diverse harm categories. A settlement that resolves shooting matters may not fit suicide matters or weapons matters. The docket may fracture along fact-pattern lines rather than resolving as one mass tort.

Injunctive relief. Where plaintiffs seek product configuration changes, meaning mandatory age verification, crisis routing, or safety escalation, any structured settlement has to resolve the injunctive component. State attorney general actions and private class components interact here, and a private settlement that ignores the enforcement track leaves the developer exposed anyway.

Damages checklist

  1. A retained forensic economist with a defensible model for lost earnings, household services, and where applicable hedonic damages.
  2. A retained life-care planner in serious-injury matters.
  3. A punitive theory with documentary support drawn from the developer's own materials.
  4. A coverage analysis of the defendant's insurance program and any reservation letters.
  5. A jurisdiction-specific analysis of punitive caps, comparative fault, and joint-and-several liability.
  6. A settlement posture memorandum modeling expected recovery under alternative scenarios: single verdict, matrix settlement, class treatment, coordinated proceeding.
  7. A note on where the first verdict in the field landed, and what it implies for the anchor in your forum.
Back to top

Chapter 8

The regulatory overlay

The tort docket is unfolding alongside state attorney general actions, a criminal investigation, a foreign sovereign in preparation, enacted state statutes, European regulation, and pending federal legislation. Each track shifts the standard of care, opens discovery, expands the plaintiff pool, or threatens preemption.

The five regulatory tracks and what each one does to a tort case
TrackCurrent stateEffect on the docket
State enforcementFlorida, Kentucky, Pennsylvania actions filed; Texas and California investigations openParallel discovery, injunctive relief that resets the standard of care
CriminalFlorida investigation opened April 21, 2026; no chargesPublic factual record; Fifth Amendment sequencing problems
Foreign sovereignBritish Columbia retained outside counsel July 7, 2026Cross-border discovery; a new category of plaintiff
Enacted state statutesCalifornia Senate Bills 243 and 53; New York, Utah, Maine disclosure lawsStatutory duties, one private right of action, discoverable filings
FederalNo comprehensive statute; AI LEAD Act pending as Senate Bill 2937Preemption risk; would classify these systems as products by statute

Three states have already sued, and more are positioned to

Florida v. OpenAI, filed June 1, 2026, is the first state action against a major developer over safety and design. Attorney General James Uthmeier's complaint alleges the company and its chief executive are "endangering and addicting children, aiding and abetting mass shooters, and coaxing users into suicide as the company pursues profit," proceeds under Florida consumer protection law, and cites the Florida State shooting as a specific instance. (BBC; AP) OpenAI removed to federal court on July 2, 2026; the state moved to remand on July 10; the motion is undecided.

Kentucky v. Character Technologies, filed January 2026 in Franklin Circuit Court, was the first state action against an AI chatbot company. It proceeds under the Kentucky Consumer Data Protection Act and consumer protection law, alleging unlawful collection of children's data without parental consent, inadequate age gating, design that induces minors to disclose sensitive information, and bots modeled on child-friendly characters engaging in sexual talk. (complaint)

Pennsylvania v. Character Technologies, filed May 1, 2026, takes a different route: unlawful practice of medicine. A bot named Emilie claimed to be a licensed psychiatrist with a degree from Imperial College London, licenses in the United Kingdom and Pennsylvania, and a fabricated Pennsylvania license number, and told a user that assessing medication was within her remit as a doctor. (NPR) The unlicensed-practice theory is now appearing in private complaints too, and it's the cleanest route around a causation fight, because the statutory violation is the wrong.

Investigations open. Texas opened a joint investigation of Meta and Character.AI on August 18, 2025 over deceptive marketing of personas as mental health tools to minors. California opened an investigation of xAI on January 14, 2026. The Federal Trade Commission issued study orders to seven companies on September 11, 2025 covering the emotional and developmental risks of companion chatbots to children and teenagers.

What a state action does for a private case

  • Consumer protection claims reach the developer's marketing and safety representations, and are less obviously subject to a Section 230 defense than content-based claims.
  • Parens patriae standing lets the state sue on behalf of its residents, particularly minors, and seek injunctive relief along with civil penalties.
  • Discovery reach. State discovery produces materials that overlap substantially with the private docket. Monitor the filings, and where possible coordinate on strategy without compromising either side's confidentiality obligations.
  • Injunctive relief. A product-design injunction, meaning age verification or safety routing requirements, reshapes the industry and with it the standard of care in private tort litigation.

The states with prior multistate social media experience, meaning California, Colorado, New York, Washington, and Illinois, are the most likely to follow. A coordinated multistate action against a major developer is the natural next escalation.

A criminal investigation with no obvious statute behind it

The Florida Office of Statewide Prosecution opened a criminal investigation of OpenAI on April 21, 2026, the first publicly disclosed criminal probe of a major generative AI developer over user-perpetrated violence. The statutory hook is Florida's aiding and abetting principal statute. Subpoenas demand policies and training materials on threats of harm, law enforcement cooperation, and crime reporting from March 1, 2024 forward, along with organizational charts and every public statement about the shooting. (Florida Attorney General)

Uthmeier's own framing of the difficulty is the clearest statement of it: "If it was a person on the other end of that screen, we would be charging them with murder. Of course, ChatGPT is not a person. But that does not absolve our office, my prosecution team, of our duty to investigate whether or not there is criminal culpability here for a corporation." (Florida Phoenix) Whether the state can construct a viable theory, through accessory liability, criminal negligence, or reckless endangerment, is the open question. No charges have been filed.

For the plaintiff: grand jury materials are generally inaccessible without a court order, the investigation may produce statements from the developer that are admissible in the civil case, and the criminal proceeding may take deposition priority for individual defendants who invoke the Fifth Amendment.

For the developer: parallel criminal exposure changes the discovery posture. Civil responses get shaped by criminal privilege considerations, individual witnesses may invoke the Fifth Amendment in civil depositions, and settlement dynamics are inevitably influenced by the criminal track.

Whether or not charges follow, the investigation is producing a public factual record that supports the state's civil action and informs private pleading. Other attorneys general are watching it as a template.

A province is preparing the first sovereign action

On July 7, 2026 the British Columbia Ministry of Attorney General announced it had retained outside counsel, CFM Lawyers and Stranch, Jennings & Garvey, to explore legal options over the Tumbler Ridge shooting. The stated basis is that the developer's safety teams flagged the perpetrator's violent prompts months before the attack and leadership didn't notify police. (Government of British Columbia)

Note the posture precisely: counsel retained, no complaint filed. Coverage describing the province as having sued runs ahead of the record. When it's filed it will be the first sovereign-plaintiff AI liability action in North America and will produce doctrine on cross-border discovery, foreign sovereign standing in American courts, and the reach of Canadian tort law over American-domiciled developers.

Expect second-wave sovereign actions. The European Union, the United Kingdom, and Australia have all identified AI safety as a national security priority. Where a mass casualty event in one of those jurisdictions is linked to an American developer, a sovereign action in that jurisdiction's home courts, with attempts to enforce here, becomes plausible. For private counsel, sovereign filings dramatically expand the discoverable record; track them on the same theories as your own cases.

Statutory duties now exist, and one of them can be sued on

The regulatory question changed in late 2025. Duties that were proposals are now enacted law.

California Senate Bill 243, signed in 2025 and effective January 1, 2026, governs companion chatbots. It requires disclosure that the user is talking to a machine, protocols to prevent suicide and self-harm content, referral to crisis services, publicly available protocols with annual reporting to the state Office of Suicide Prevention, and for minors, break reminders every three hours and reasonable steps against sexually explicit content. It carries a private right of action: statutory damages of at least one thousand dollars per violation, injunctive relief, and attorney's fees. For a practitioner, that's the most useful development in the statute book, because it converts a design failure into a claim that doesn't require proving causation of a death.

California Senate Bill 53, the Transparency in Frontier Artificial Intelligence Act, applies to large frontier developers. It requires publication of an annual frontier AI framework and pre-deployment transparency reports summarizing catastrophic risk assessments, their results, and the role of any third-party evaluators, and it requires reporting critical safety incidents to the state within fifteen days, or twenty-four hours where danger is imminent. Enforcement runs through the attorney general at up to one million dollars per violation, with no private right of action. Its value to a tort case is evidentiary: it forces dated, specific, public admissions about what the developer knew.

Other states. New York requires reasonable efforts to detect and address self-harm content, with disclosure at the start of a conversation and every three hours. Utah and Maine have enacted disclosure-only regimes. Illinois restricts the use of these systems in therapy contexts.

The European Union. Regulation (EU) 2024/1689 categorizes systems by risk and imposes tiered obligations, with specific requirements for general-purpose models on training data documentation, safety evaluation, incident reporting, and systemic risk assessment. It isn't enforceable in American courts, but it shapes standard-of-care evidence here: where the regulation mandates a practice and the developer complies for European deployments, plaintiffs can argue the developer knew the practice was feasible and chose not to apply it domestically. Its serious-incident reporting will generate a public record of harms usable in American litigation. Member state transposition of the revised product liability directive, which brings software within its scope, is due by December 2026.

Federal legislation would change the framework, not just the rules

No comprehensive federal statute has been enacted.

The AI LEAD Act, Senate Bill 2937, introduced September 29, 2025, would classify these systems as products by statute and create a federal cause of action available to the Attorney General, state attorneys general, individuals, and classes. Design defect claims would require a reasonable alternative design unless the design is manifestly unreasonable. Noncompliance with safety regulations would presume defect. Risks would be presumed non-obvious to users under eighteen, which defeats the open-and-obvious defense for minors. Liability couldn't be waived by contract, which would end the arbitration and terms-of-service fights. It sets a floor rather than a ceiling, so states could go further, and it would apply to actions commenced after enactment including for pre-enactment harms. (bill text)

Section 230 amendment. Proposals to exclude generative output from the immunity have been introduced in successive Congresses without reaching a floor vote. Enactment would moot the immunity defense in this docket without resolving the First Amendment or proximate cause questions.

Youth protection. Proposals extending online safety requirements to generative systems would impose age verification and content moderation enforceable by the Federal Trade Commission and state attorneys general. Compliance records would be discoverable and would shape the standard of care in suicide and self-harm matters especially.

Preemption. Any comprehensive federal statute raises preemption questions against the state tort claims in this docket. Monitor draft legislation for express preemption clauses and be prepared to argue against implied preemption under Wyeth v. Levine and its progeny. Preemption practice is routine in pharmaceutical and medical device litigation and translates directly.

Voluntary commitments are admissions, and they're dated

  • The July 2023 voluntary White House commitments, signed by seven leading developers, including commitments to internal and external red-teaming, information sharing about safety incidents, and public reporting on capabilities and limitations.
  • The Bletchley Declaration of November 2023 and the subsequent Seoul and Paris statements, establishing international consensus on which categories of risk require serious attention.
  • Frontier Model Forum publications, particularly on safety evaluations, responsible scaling policies, and incident reporting norms.
  • Developer-specific responsible scaling policies and release guidelines.
  • Published safety benchmarks, including the CT-AI Benchmark released July 1, 2026 and the broader benchmark ecosystem.

Each is admissible as an admission or as standard-of-care evidence. Build the habit of monitoring the commitment repositories monthly and preserving the versions that were public in the relevant window for each matter. A commitment that has since been quietly revised is worth more to your case than the current one.

Insurance regulation is the fifth track and moves on its own clock

State insurance regulators have begun scrutinizing AI liability underwriting, and New York, California, and Colorado have published guidance on AI risk in various contexts. As insurers reprice coverage for exposed enterprises, the availability and terms of that coverage will shape developer conduct and, indirectly, the tort environment. Treat it as a distinct track with its own timeline rather than as a footnote to the coverage analysis in Chapter 7.

Five practical consequences for the tort docket

  1. Standard of care. Every regulatory instrument is available as standard-of-care evidence. Plaintiffs cite them. Defendants should be ready to explain deviation.
  2. Admissions. Every developer statement in a regulatory forum, meaning securities filings, congressional testimony, European compliance disclosures, and state incident reports, is admissible as an admission.
  3. Discovery leverage. Parallel proceedings expand the accessible record. Map the regulatory landscape and identify every proceeding that touches your matter.
  4. Settlement pressure. Regulatory exposure amplifies it. A pending state action or criminal investigation frequently accelerates civil settlement.
  5. Preemption watch. Keep federal legislation on the periodic status memorandum for every open matter.
Back to top

Chapter 9

Where the doctrine is headed

This docket is measured in quarters, not decades. Eight rulings will settle most of what's open. Behind them, a second generation of cases is already forming that will test the same doctrine on harder facts.

Eight rulings that will decide the field

1. The first Section 230 ruling on generative output that reaches an appellate court. Bouck is a district court decision on advertising copy. Anderson and Patterson disagree on the adjacent question. Whichever appellate court rules first on the generative question will produce the anchor precedent every later court cites, and the doctrine will consolidate quickly around it.

2. The first appellate ruling on whether a chatbot is a product. Judge Conway said yes at the pleading stage and the case settled before review. The first appellate affirmation or rejection determines whether the central pleading move survives at scale. If it survives, strict liability becomes the docket's default. If it doesn't, plaintiffs regroup around negligence, negligent entrustment, and consumer protection, which is exactly the path the only completed jury verdict in the adjacent field already took.

3. The first dispositive rulings in the coordinated California proceeding. Ten-plus cases before one judge, with rulings expected in late 2026. A single order there will do more to set the field than any three isolated decisions.

4. The first punitive verdict against a developer. Whatever its size, it sets the exposure ceiling and drives the settlement posture of every open matter. It will also generate post-verdict constitutional review that shapes all later punitive practice here.

5. The first appellate ruling on personal executive liability. The decisions to name a chief executive personally will eventually produce a ruling on the standard. That determines whether individual defendants are a routine feature of this docket or an outlier.

6. The first ruling on the Florida criminal theory. Whether a state can construct a viable corporate criminal theory, and whether others follow, is the exposure question hanging over the industry. Even a reasoned decision declining to charge would shape prosecutorial practice.

7. The first appellate ruling on the publicly available information defense. Whether comparative availability defeats causation as a matter of law, or is merely a jury argument, is a first-order question in every fact pattern.

8. The first ruling on a duty to warn law enforcement. Whether a conversational system owes any duty to alert authorities when its own systems flag operational planning is the horizon question. The Tumbler Ridge facts are the paradigm test case, and Smith & Wesson's affirmative-act requirement is the reason the theory has to run in negligence rather than aiding and abetting.

A ninth belongs on the list for the defense bar: whether Rule 37(e) applies to model checkpoints, safety configurations, and classifier states as it applies to ordinary business records. That will be contested in every early matter and no published opinion answers it.

The next generation of cases

The current docket is dominated by shootings, suicides, and bombings. The next wave is already visible in isolated filings.

Non-consensual imagery and synthetic sexual abuse material. This is arriving faster than any other category. A consolidated action against xAI, amended in July 2026 to add Stability AI, alleges the systems were used to generate non-consensual imagery of real women and minors, on the theory that the developers chose deliberately weaker guardrails. It shares the Section 230, First Amendment, and product liability architecture with the personal injury docket. Treat it as a doctrinal sibling, not a separate field.

Unlicensed practice claims. Unlicensed practice of medicine and of psychology are now pleaded in both private complaints and state enforcement. They're attractive because the statutory violation is the wrong, which shortens the causation fight considerably.

Companion and relationship harm. Companion products that build intense parasocial relationships, particularly with minors, will produce claims that go beyond suicide to coercive control, isolation, and emotional dependency as a compensable injury.

Agentic and multi-agent harms. Where causation runs through several systems acting autonomously, an assistant acting on another system's output, or a system composing and executing actions across tools, the causation analysis gets structurally harder and the developer-against-deployer allocation becomes the central pleading choice.

Professional liability. Against attorneys, physicians, and other professionals who used these tools and produced harmful outputs, with the developer named as co-defendant. The question is joint allocation between the professional user and the tool provider. Malpractice carriers are already repricing.

Fraud and financial harm. As agentic systems execute transactions, plaintiffs will sue the developer when those transactions harm third parties. The doctrinal fit is imperfect, but the standard-of-care and design-defect frameworks translate.

Discrimination claims. For systems deployed in employment, credit, housing, and public benefits. The regulatory overlay is denser than in the personal injury docket; the private tort machinery is similar.

Cross-border harms. As foreign plaintiffs sue American developers and American plaintiffs sue foreign ones, jurisdiction and conflict of laws move to the foreground. Refresh your working knowledge of Bristol-Myers Squibb v. Superior Court and its progeny.

Model poisoning. Where a third party has manipulated training data or a fine-tuning pipeline to produce harmful outputs, causation runs through both the developer's product and the attacker's conduct. Still hypothetical, and the natural next escalation.

Defamation. Well developed in the Section 230 scholarship and under-represented in the harm docket. As these systems are used in journalism, background research, and reputational scoring, the cases will accumulate. The doctrinal architecture is largely settled from the pre-AI era; the new questions are about attribution.

What defense counsel should be doing now

  • Data retention. Every retained record, meaning training data, moderation logs, red-team reports, and executive communications, is a potential exhibit. Review retention policies with counsel and hold a defensible posture.
  • Safety governance. Documented, board-level safety governance that can be described to a jury is the single strongest protection against a punitive verdict. Keep minutes, decision memoranda, and independent advisor engagements in a form counsel can produce and testify to.
  • Incident response. A written protocol for law enforcement notification when moderation flags cross a stated threshold. Two of the leading complaints allege no such notification was made, and one of them has a public apology attached to it.
  • Warnings. Model cards and disclosures targeted at the specific harm categories in this docket, drafted to satisfy the hazard, consequence, and avoidance framework the plaintiff's safety engineer will apply.
  • Guardrail change management. The guardrail-decay theory has made safety configuration change management a first-order documentation problem. Every change needs a documented rationale, an approver, and a rollback plan.
  • Coverage. Review the directors and officers, general liability, and cyber programs with coverage counsel against these specific exposures.
  • Cross-matter learning. Absorb rulings and verdicts from early matters into product and policy decisions. A defense team that treats each case in isolation repeats avoidable mistakes.
  • Statutory compliance as a defense asset. The state transparency and companion-chatbot statutes cut both ways. A developer that documents compliance builds the record for a state-of-the-art defense. One that doesn't hands the plaintiff a negligence per se theory.

What plaintiffs' counsel should be doing now

  • Case selection discipline. The firms driving this docket are selecting cases with strong chat records, clear moderation failures, and identifiable victims. Weak cases at the pleading stage produce bad precedent for everyone. Not every referral should be filed.
  • Coordination. The California proceeding is already running with co-lead counsel and a steering committee. Join it proactively rather than duplicating discovery that's already been taken.
  • Regulatory partnership. State enforcement and private litigation reinforce each other. Counsel who build working relationships with enforcement offices are producing better discovery outcomes.
  • Expert investment. The panel is the case. Retaining a nameplate academic instead of a communicative technical expert, skimping on reproduction work, or skipping the safety engineer are the common errors, and none of them will survive the Rule 702 practice the defense bar is now developing.
  • Chat record fidelity. The case rises or falls on the specificity of the record pleading. Build every complaint around the most specific and load-bearing content you can plausibly plead and later prove.
  • Preservation discipline. A preservation demand at every intake. A preservation index in every case file. A preservation-gap analysis in every deposition preparation.
  • Statutory claims. Where the conduct falls within an enacted state chatbot statute with a private right of action, plead it. It survives whether or not the product theory does.
  • The denominator. Prepare the answer to the argument that millions of people use these systems without harm. A jury that uses the product every day has already heard it, and one of them has already said so out loud in open court.

What the regulatory response would look like if it comes

Six proposals recur across the leading policy institutions. None originates here.

  • Mandatory serious-incident reporting for general-purpose models above a stated capability threshold, on the model of aircraft incident reporting.
  • Mandatory age verification for products with documented youth-harm exposure, at a technical standard a court can enforce.
  • Mandatory disclosure of safety evaluations for major releases, specific enough to permit independent scrutiny.
  • A statutory duty to warn law enforcement when moderation systems detect specific-threat operational planning, adapted from the Tarasoff line.
  • Statutory clarification of Section 230's reach over generative output, through targeted amendment rather than through a decade of litigation.
  • A federal minimum product safety standard for general-purpose models, with preemption limited to the least productive state variance.

Each is doctrinally coherent and technically feasible. California has already enacted versions of the first and third. The federal bill pending as Senate Bill 2937 would enact a version of the sixth.

The question underneath all of it

This docket is a proxy fight over a question the law has faced before. When does a manufacturer become responsible for the foreseeable misuse of a product it designed?

The answer in every prior wave, from firearms to pharmaceuticals to social media, was shaped by the specific harm patterns, the specific plaintiffs, and the specific evidence that reached juries first. This wave is producing exactly those inputs now. The doctrine that emerges will be with us for a generation.

Three questions decide these cases, and they're the same three that decide every product safety case. Was the harm foreseeable? Was it preventable? Did the knowledge exist? What's unusual here is that the defendants answered all three in writing before anyone was hurt. They published the system cards documenting the risk category. They built the guardrails, which proves prevention was feasible. They ran the red teams and wrote up the results. In firearms and pyrotechnics you spend a year reconstructing what the maker knew. In this field the maker wrote it down and posted it.

The book that comes after this one will be written by the appellate courts. What they say about Joshi, Raine, Garcia, Tumbler Ridge, and the cases not yet filed will govern the practice of every lawyer, expert, insurer, and developer in the field. The task in the meantime is to bring those courts the fullest and clearest record on which to decide.

The cases are being filed now. The evidence is being preserved now. The experts are being retained now. The record that governs the doctrine is being built, case by case, in the ordinary work of the ordinary litigator. That's where the doctrine actually gets made.

Back to top

Appendix A

Table of cases

Status current through July 31, 2026. Every entry has been checked against a court docket, a government release, or an established news organization. Several of the highest-ranking case trackers online are lead-generation sites carrying fabricated or conflated entries; nothing here rests on one alone. Confirm current status before you rely on any of it.

Private civil actions

United States private civil actions against artificial intelligence developers
CaseCourt and numberFiledSubjectStatus
Garcia v. Character TechnologiesM.D. Fla., 6:24-cv-01903-ACC-DCIOct. 22, 2024Suicide of Sewell Setzer III, 14Motion to dismiss denied May 21, 2025 (Conway, J.). Settled and closed Jan. 7, 2026 with four related cases.
A.F. v. Character TechnologiesE.D. Tex., 2:24-cv-01014Dec. 10, 2024Self-harm and sexual content, two minorsSettled Jan. 2026.
Raine v. OpenAIS.F. Super. Ct., CGC-25-628528Aug. 26, 2025Suicide of Adam Raine, 16Amended Oct. 22, 2025 to plead intentional misconduct. Coordinated in JCCP 5431.
Peralta v. Character TechnologiesD. Colo., 1:25-cv-02907Sep. 16, 2025Suicide of Juliana Peralta, 13Reported settled Jan. 2026; individual dismissal unconfirmed.
Shamblin, Lacey, Enneking, Fox, Irwin, Madden, Brooks v. OpenAIS.F. and L.A. Super. Ct.Nov. 6, 2025Four deaths, three survivorsCoordinated in JCCP 5431. Plead civil assisted suicide and involuntary manslaughter counts.
First County Bank v. OpenAIS.F. Super. Ct., CGC-25-631477Dec. 11, 2025Greenwich murder-suicide; estate of Suzanne AdamsCoordinated in JCCP 5431.
Lyons v. OpenAI FoundationN.D. Cal., 3:25-cv-11037Dec. 29, 2025Same incident; estate of Stein-Erik SoelbergMotion to dismiss or stay under Colorado River denied Apr. 13, 2026 (Seeborg, C.J.).
Gavalas v. GoogleN.D. Cal.Mar. 4, 2026Suicide of Jonathan Gavalas, 36; alleged mass casualty promptingPending. First wrongful death action over Gemini.
Tumbler Ridge complaints (seven)N.D. Cal.Apr. 29, 2026British Columbia school shooting, Feb. 10, 2026Pending. Allege a June 2025 flag and a decision not to notify police. Name Sam Altman.
Joshi v. OpenAI FoundationN.D. Fla., 4:26-cv-00222-MW-MJFMay 10, 2026Florida State shooting; estate of Tiru ChabbaResponse deadline extended to July 13, 2026. Free dockets show no entries after July 7, 2026.
Turner-Scott v. OpenAIS.F. Super. Ct.May 12, 2026Fatal drug interaction after dosing guidancePending. Pleads unlicensed practice of medicine.
Grant v. OpenAI and AltmanLeon Cty. Cir. Ct., Fla.June 2026Florida State shooting survivorPending.
Carrier v. OpenAI and AltmanS.F. Super. Ct.June 11, 2026Suicide of Alice CarrierPending. Seeks injunction requiring session termination on suicidal ideation.
Florida State survivor actions (two)Federal; docket numbers unconfirmedJuly 14, 2026Shooting survivorsPending. First in the docket to seek punitive damages and name Altman.

Coordination. Judicial Council Coordination Proceeding 5431, In re ChatGPT Product Liability Cases, granted February 3, 2026, San Francisco Superior Court, Judge Ethan Schulman. Case Management Order Number 1 entered August 4, 2026 appointing four co-lead plaintiffs' counsel and a steering committee. There's no federal multidistrict litigation.

Government enforcement

State and federal enforcement
ActionForumDateTheory
Texas investigation of Meta and Character.AITexas Attorney GeneralAug. 18, 2025Deceptive marketing of personas as mental health tools to minors
Federal Trade Commission study ordersSeven companiesSep. 11, 2025Emotional and developmental risks of companion chatbots to minors
Kentucky v. Character TechnologiesFranklin Cir. Ct.Jan. 2026Consumer data protection and consumer protection; children's data and age gating
California investigation of xAICalifornia Attorney GeneralJan. 14, 2026Non-consensual sexualized imagery of women and children
Florida criminal investigation of OpenAIOffice of Statewide ProsecutionApr. 21, 2026Aiding and abetting principal statute. No charges filed.
Pennsylvania v. Character TechnologiesPennsylvania state courtMay 1, 2026Unlawful practice of medicine; fabricated license number
Florida v. OpenAI and AltmanFla. circuit court; removed to S.D. Fla. July 2, 2026June 1, 2026Deceptive and unfair trade practices, public nuisance, product liability. Remand undecided.

Foreign and sovereign actions

  • Province of British Columbia. Outside counsel retained July 7, 2026, CFM Lawyers and Stranch, Jennings & Garvey, to explore legal options over the Tumbler Ridge shooting. No complaint filed as of July 31, 2026. (Government of British Columbia)

Criminal matters that carry the docket

  • State v. Phoenix Ikner. Two counts of first-degree murder and seven counts of attempted first-degree murder, indicted May 14, 2025. Death penalty noticed June 5, 2025. Trial set for October 19, 2026 before Judge Lance Neff. Roughly 270 chatbot messages are designated evidence.
  • United States v. Jonathan Rinderknecht. Three federal arson counts over the Palisades Fire. Chatbot logs were central evidence. Mistrial June 26, 2026 on a jury hung 10 to 2 for acquittal. Retrial set October 19, 2026. (CNN)
  • State v. Hisham Abugharbieh. Two counts of first-degree premeditated murder, Hillsborough County, Florida. Prosecutors introduced chatbot queries about body disposal, firearms, and vehicle identification numbers as premeditation evidence. Pleaded not guilty May 18, 2026.
  • Las Vegas Cybertruck bombing. Matthew Livelsberger, January 1, 2025. Police publicly identified chatbot queries as part of the planning record. No prosecution; the defendant died before detonation. (Las Vegas Metropolitan Police Department)
  • Regina v. Jaswant Singh Chail. Windsor Castle, December 25, 2021. Guilty pleas to treason, threats to kill, and possession of an offensive weapon after roughly 5,000 messages with a Replika companion. Nine years in prison plus five years of extended supervision, October 2023. (BBC)
  • India ricin plot. Medical consultant arrested over alleged Islamic State ricin production after reported chatbot and AI-powered search consultation.

Prior authorities that decide these cases

  • Fair Housing Council of San Fernando Valley v. Roommates.com, LLC, 521 F.3d 1157 (9th Cir. 2008) (en banc). The material contribution test for Section 230. (opinion)
  • Anderson v. TikTok, Inc., No. 22-3061 (3d Cir. Aug. 27, 2024). Algorithmic recommendation as the platform's own first-party expression.
  • Patterson v. Meta Platforms, Inc., 2025 NY Slip Op 04447 (4th Dep't July 25, 2025). Buffalo shooting claims dismissed on Section 230 and the First Amendment. (opinion)
  • Bouck v. Meta Platforms, Inc., 2026 WL 810036 (N.D. Cal. Mar. 24, 2026). Section 230 doesn't reach AI-generated advertising content.
  • Moody v. NetChoice, LLC, 603 U.S. 707 (2024). Algorithmic curation as First Amendment editorial expression. (opinion)
  • Brown v. Entertainment Merchants Association, 564 U.S. 786 (2011). Video games are protected speech; interactivity is a matter of degree.
  • Rice v. Paladin Enterprises, Inc., 128 F.3d 233 (4th Cir. 1997). Civil aiding and abetting liability for operational instruction, on a stipulation of intent and knowledge. (opinion)
  • James v. Meow Media, Inc., 300 F.3d 683 (6th Cir. 2002). Media defendants not liable after a school shooting; expressive works aren't products in the sense of their communicative content.
  • Winter v. G.P. Putnam's Sons, 938 F.2d 1033 (9th Cir. 1991). Ideas and expression aren't products.
  • Twitter, Inc. v. Taamneh, 598 U.S. 471 (2023). Aiding and abetting under 18 U.S.C. ยง 2333.
  • Smith & Wesson Brands, Inc. v. Estados Unidos Mexicanos, No. 23-1141 (June 5, 2025). Aiding and abetting requires conscious and culpable participation, ordinarily through affirmative acts.
  • Soto v. Bushmaster Firearms International, LLC, 331 Conn. 53 (2019). Wrongful marketing claims survive federal firearms immunity; negligent entrustment requires the direct recipient's unfitness. (opinion)
  • Daubert v. Merrell Dow Pharmaceuticals, 509 U.S. 579 (1993); Kumho Tire Co. v. Carmichael, 526 U.S. 137 (1999); Federal Rule of Evidence 702.
  • BMW of North America, Inc. v. Gore, 517 U.S. 559 (1996); State Farm Mutual Automobile Insurance Co. v. Campbell, 538 U.S. 408 (2003); Philip Morris USA v. Williams, 549 U.S. 346 (2007). Constitutional review of punitive damages.
Back to top

Appendix B

Timeline of the docket

February 2024 through July 2026
DateEvent
Feb. 28, 2024Sewell Setzer III, 14, dies. The Garcia matter follows.
Oct. 22, 2024Garcia v. Character Technologies filed in the Middle District of Florida.
Dec. 10, 2024A.F. v. Character Technologies filed in the Eastern District of Texas.
Jan. 1, 2025Matthew Livelsberger detonates a Cybertruck outside the Trump International Hotel, Las Vegas.
Apr. 11, 2025Adam Raine, 16, dies. The Raine matter follows.
Apr. 17, 2025Florida State shooting. Tiru Chabba and Robert Morales killed, six wounded.
May 21, 2025Garcia motion to dismiss denied. First AI chatbot bodily injury case to survive.
June 5, 2025Supreme Court decides Smith & Wesson Brands v. Estados Unidos Mexicanos.
June 2025OpenAI's systems flag the Tumbler Ridge shooter's account, per the complaints.
July 25, 2025Patterson v. Meta decided in the New York Appellate Division, Fourth Department.
Aug. 18, 2025Texas opens its investigation of Meta and Character.AI.
Aug. 26, 2025Raine v. OpenAI filed in San Francisco Superior Court.
Sep. 11, 2025Federal Trade Commission issues study orders to seven companies.
Sep. 16, 2025Matthew Raine testifies before the Senate Judiciary Committee.
Sep. 29, 2025The AI LEAD Act introduced as Senate Bill 2937.
Oct. 22, 2025Raine amended complaint pleads intentional misconduct on the guardrail relaxation theory.
Nov. 6, 2025Seven further actions filed against OpenAI: four deaths, three survivors.
Dec. 11, 2025First County Bank v. OpenAI filed over the Greenwich murder-suicide.
Dec. 29, 2025Lyons v. OpenAI Foundation filed in the Northern District of California.
Jan. 1, 2026California Senate Bill 243 takes effect.
Jan. 7, 2026Garcia and four related cases settle. First settlements in AI harm litigation.
Jan. 2026Kentucky sues Character Technologies. California opens its xAI investigation.
Feb. 3, 2026JCCP 5431 coordination granted over ten actions.
Feb. 10, 2026Tumbler Ridge, British Columbia school shooting. Eight killed.
Mar. 4, 2026Gavalas v. Google filed.
Mar. 24, 2026Bouck v. Meta decided in the Northern District of California.
Mar. 25, 2026Los Angeles jury finds Meta and Google negligent in design in JCCP 5255. Six million dollars.
Apr. 13, 2026Colorado River abstention denied in Lyons.
Apr. 21, 2026Florida opens its criminal investigation of OpenAI.
Apr. 29, 2026Seven Tumbler Ridge complaints filed in the Northern District of California.
May 1, 2026Pennsylvania sues Character Technologies over unlawful practice of medicine.
May 10, 2026Joshi v. OpenAI Foundation filed in the Northern District of Florida.
June 1, 2026Florida v. OpenAI and Altman filed.
June 26, 2026Mistrial in the Palisades Fire prosecution. Jury hung 10 to 2 for acquittal.
July 1, 2026Tech Against Terrorism releases the CT-AI Benchmark at the United Nations.
July 7, 2026British Columbia retains outside counsel over the Tumbler Ridge shooting.
July 10, 2026Cambridge report on Boko Haram use of commercial chatbots published.
July 13, 2026Extended deadline for OpenAI's response in Joshi.
July 14, 2026Two Florida State survivor actions filed. First to seek punitives and name Altman.
Back to top

Appendix C

Glossary

Agentic system
A system that plans and executes multi-step actions on a user's behalf, usually through tool use or programming interfaces. Distinct from a chatbot that only generates text.
Alignment, or safety training
The process, typically involving reinforcement learning from human feedback and rule-based refinement, by which a base model is shaped to refuse certain requests and follow policy. It changes the model's weights, which is what distinguishes it from moderation.
Classifier
A model that assigns a category or score to inputs or outputs. In safety architectures, classifiers detect violent content, self-harm content, weapons content, and other risk categories.
Deployer
An entity that operates or integrates a system, often a downstream developer using a foundation model through a programming interface. Distinct from the foundation model provider, and frequently the party that controls the system prompt and the safety filter.
Foundation model
A large, general-purpose model trained on broad data and adapted for downstream applications. Sometimes called a base model.
Guardrail
Any safety measure applied to the system, from safety-training-based refusals to filters that inspect output at the time of use to human review.
Hallucination
An output stated confidently and wrong or fabricated. In this docket it matters mainly in defamation and professional liability adjacencies.
Jailbreak
A prompt or technique used to induce a system to produce output its safety measures would normally block.
Large language model
A model trained on text to predict continuations, which is what produces the conversational behavior at issue in these cases. Its outputs are non-deterministic at typical settings, which is a first-order evidentiary problem rather than a technicality.
Model card, or system card
A structured document published by a developer describing a model's intended use, evaluation results, and known limitations. Analogous to a product data sheet, and admissible as an admission.
Moderation
The system, usually classifiers plus human review, that inspects inputs and outputs for policy violations and generates flags, refusals, or escalations. It sits on top of the model rather than inside it.
Red team
A group tasked with adversarially probing a system to find safety failures before deployment. Internal red teams are employees. External red teams are contracted third parties, and they produce written deliverables.
Reinforcement learning from human feedback
A training technique in which human preferences shape model output. The mechanism behind most safety training.
Retrieval-augmented generation
An architecture in which a model retrieves external content and grounds its response in that content. Relevant to Section 230 because it reintroduces genuine third-party material into the output.
System prompt
Instructional text, usually invisible to the user, that frames a session and shapes behavior. Distinct from the user's prompt, and typically controlled by the deployer.
Trust and safety
The organizational function that develops and enforces content policy, safety measures, and law enforcement referral processes. The team whose documents matter most in discovery.
Back to top

Appendix D

Primary sources to keep in the folder

Complaints and docket materials

  • Joshi v. OpenAI Foundation complaint, May 10, 2026. (PDF)
  • Raine v. OpenAI complaint, August 26, 2025. (PDF)
  • Garcia v. Character Technologies order on the motions to dismiss, May 21, 2025. (opinion)
  • JCCP 5431 coordination order, February 3, 2026. (PDF)
  • Matthew Raine's Senate Judiciary testimony, September 16, 2025. (PDF)

Case law

  • Fair Housing Council v. Roommates.com, 521 F.3d 1157 (9th Cir. 2008). (opinion)
  • Moody v. NetChoice, 603 U.S. 707 (2024). (opinion)
  • Patterson v. Meta Platforms, 2025 NY Slip Op 04447. (opinion)
  • Rice v. Paladin Enterprises, 128 F.3d 233 (4th Cir. 1997). (opinion)
  • Soto v. Bushmaster Firearms, 331 Conn. 53 (2019). (opinion)

Government and standards material

  • Congressional Research Service, Section 230 and generative artificial intelligence. (LSB11097)
  • California Senate Bill 53, the Transparency in Frontier Artificial Intelligence Act, and the frontier frameworks and transparency reports published under it.
  • California Senate Bill 243, and the protocols and annual reports filed under it.
  • The AI LEAD Act, Senate Bill 2937. (bill text)
  • National Institute of Standards and Technology AI Risk Management Framework 1.0 and the Generative AI Profile.
  • ISO/IEC 42001. European Union Regulation 2024/1689. The revised European product liability directive.
  • The July 2023 voluntary White House commitments and the developer-specific policies published since.
  • Las Vegas Metropolitan Police Department Cybertruck release. (link)
  • Florida Attorney General releases on the civil action and the criminal investigation. (link)
  • Government of British Columbia release on retaining counsel. (link)

Safety evidence and trackers

  • Model cards and system cards for every version relevant to your matter, captured in the version that was public during the relevant window.
  • CT-AI Benchmark and case tracker, Tech Against Terrorism, July 1, 2026. (link)
  • Cambridge Programme on AI Science and Policy, report on Boko Haram use of commercial models, July 10, 2026. (link)
  • Bloomberg chatbot harm tracker. (link)

Commentary worth keeping

  • American Bar Association, Business Law Today, "Beyond the Search Bar," November 2024. (link)
  • Fortune, Quartz, and Daily Journal on Section 230's application to generative output. (Fortune; Quartz; Daily Journal)
  • New York Times on the duty to warn question. (link)
  • Moody's on coverage implications. (link)
Back to top

Retention

Reaching the author

Steve Wolf works as an expert witness in firearms, pyrotechnics, fire, stunts, on-set safety, wildfire, theatrical rigging, and now artificial intelligence liability, applying the same three questions to each: was the harm foreseeable, was it preventable, and did the knowledge exist. He bills for his time, not his opinion.

Back to top