[DigitalToday reporter Chi-gyu Hwang (황치규)] If AI breaks free of control and causes an incident, who should be held responsible? It may seem simple to pin it on the company that made the AI, but experts say it is not as straightforward as it sounds.
Harm caused by AI is so new that there are not many cases.
Since July, incidents have followed in which AI models made by OpenAI, Anthropic and others hacked multiple companies and even tampered with government websites without the developers knowing. That has brought the question to the fore in the tech world. For now, calls are growing that developers should be responsible when AI causes trouble.
Prominent figures such as Nvidia CEO Jensen Huang (젠슨 황), venture investor and key White House adviser David Sacks (데이비드 색스), and Lina Khan (리나 칸), who served as chair of the Federal Trade Commission under the Biden administration, say AI companies should bear legal liability.
In the United States, courts can hold companies legally responsible under consumer protection laws when harm results from corporate negligence or product defects. Courts can also assign additional responsibility to other individuals or organisations involved in a case.
Khan said via social media platform X, formerly Twitter, that there is no exception for AI under laws already in force.
Legal action targeting AI developers also appears to be gathering pace. Public interest legal group LASST (Legal Advocates for Safe Science and Technology) filed a lawsuit against OpenAI in California Superior Court over an incident in which an OpenAI agent hacked Hugging Face.
Florida's attorney general asked a state court to block OpenAI from developing a new model without safety measures approved by an outside group. California's attorney general sent a subpoena to OpenAI.
The political mood also appears to be shifting. Senator Josh Hawley said at a congressional hearing that it needs to be made clear that AI agents, like individuals or companies, are responsible for consumer harm, adding that there is no need to create an entirely new system to do so.
Woodrow Hartzog (우드로 하르초그), a professor at Boston University who studies technology law, said that because safeguards around AI are relatively lacking, moves to hold AI companies legally responsible are likely to continue.
By common sense, it may seem natural for AI companies to be responsible for damage caused by AI technology that escapes control. If an AI agent hacked another company during testing, the developer is likely to be held responsible. Liability could be even greater if the developer knew in advance about the hacking risk.
Even so, applying existing legal systems that examine human intent or what someone knew to situations where AI acts on its own could be a different matter. Catherine Sharkey (캐서린 샤키), a law professor at New York University, said cases involving physical harm, such as medical devices equipped with AI, can be resolved more easily under existing legal principles, but agentic AI that judges and moves on its own needs closer examination of how far current law can reach.
A situation in which an open-source model, whose code anyone can fix, causes an incident could also be a delicate issue.
AI's inherently unpredictable nature is another obstacle. Liability for negligence looks at whether a company could have foreseen potential harm, and it may be difficult to prove that if an AI model engaged in dangerous behaviour for the first time, the New York Times reported, citing Ryan Calo (라이언 칼로), a law professor at the University of Washington.
It is also not easy to prove intent required for some criminal punishment. Calo said, "Victims can exist without perpetrators." Among lawsuits over harm caused by AI, cases drawing attention involve chatbots encouraging teenagers to self-harm, leading to suicide.
Parents filed lawsuits against OpenAI and startup CharacterAI, arguing the companies are responsible. The companies involved are advancing defence arguments used by other tech firms. They say chatbot statements are protected speech under the First Amendment and are also covered by Section 230 of the Communications Decency Act. Section 230 protects online platforms from legal liability for content posted by users.
In the CharacterAI case, the U.S. District Court for the Middle District of Florida ruled last year that the CharacterAI model did not generate expression protected by the First Amendment. In another case, the New York Times reported that there is still no conclusion on whether Section 230 of the Communications Decency Act can be applied.