When AI Screws Up, Who is Liable?
I just saw an item on the news that talked about Waymo starting to run driverless cars in Boulder, Colorado. When the police were asked who was liable if the driverless car got into an accident, the answer was we don’t know and we would ask the Attorney General. Likely, if a driverless car crashes into someone and kills them, there is no criminal liability under current law. Waymo, in this case, says that if that happens they will write a check, but that probably doesn’t resolve the issue for the victim’s family when the culprit’s insurance company writes a check. This is not a Waymo issue, this is an AI issue.
When both Anthropic and OpenAI admitted that their AIs went rogue and successfully hacked multiple companies, who is liable. Likely, their insurance carriers will write a check, but the idea of criminal prosecution is to act as a deterrent. Will a check written by a company’s insurance carrier act as a deterrent?
Today, Meta joined the club and admitted that their AI, too, hacked another company.
THIS IS UNCHARTED TERRITORY!
That means that victims’ lawyers and district attorneys will need to get very creative and whether a judge or jury will lean into their creativity is unclear.
The Computer Fraud and Abuse Act is a major criminal law that is used to go after hackers. It requires a hacker to KNOW that they are accessing a computer without authorization. Does a piece of software have the ability to “know”?
While the AG, DoJ or whoever might be more motivated if the AI was Chinese, that is mostly political theatre, since it is highly unlikely that the Chinese government would hand over a Chinese company to an American court.
Credit: Tech Crunch
Bottom line is that these companies could get away with murder, legally.
Now lets make this even messier.
Insurance companies like “knowable” risk. The risk from an AI doing something bad is both unknowable and unbounded. There is also very little data to analyze to figure out the risk.
As a result, major insurers are excluding AI-related losses from not only CYBER policies, but also E&O and D&O policies.
Adding AI governance – documented and executed governance – might help getting coverage, but it might not.
Recently companies like AIG, Great American and WR Berkley have added new exclusions and limitations for AI-related claims. They say AI risk is too unpredictable, too opaque and too potentially catastrophic to insure under conventional policies. Part of this can only be resolved by the AI companies. Will they?
This is important whether you are writing AI software or buying AI software.
The exclusions run the gamut from ABSOLUTE AI exclusions that fully exclude any claim from the use, output, training, advice or decision making using AI to they may create policy sub-limits or increase premiums.
At this point running naked (no insurance) is not a great strategy unless you have very deep pockets and are willing to write a large check, so you may have to search or negotiate.
If you need assistance, please contact us.
Credit: Galkin Law
