·

—

Liability Is the Bill, Not the Brake

A lawsuit is a post-mortem. Governance is a pulse check.

I. The third clock

This is Part 2 of Stop Petting the SuperIntelligence. Part 1 argued that letting frontier AI rip is a dead end. This part takes on the alternative Washington has actually chosen: let the courts sort it out.

A leading weekly put the problem crisply this week. The administration’s advisers argue that today’s liability laws are enough to regulate AI; yet by the time courts issue a ruling, the technology may have transformed the economy or caused a cataclysm. There must, it concluded, be a better way.

In Part 1 I set out three clocks of accountability. The first runs before deployment, the second at the moment an agent acts, the third after harm. Liability is the third clock. It is the only one Washington is relying on, and it is the only one that, by design, can never stop anything.

ClockInstrumentsFailure modeCan it say no?
Before deploymentLicences, evaluations, if-then commitments, third-party auditsModels learn to spot the testOnly at launch
At executionRuntime checkpoint, Ring Zero kernel, per-action authorisationVoluntary todayYes
After harmLawsuits, fines, insurance claims, incident reportsYears late; no one left to pay for a catastropheNo
Three clocks of accountability: only the middle one can refuse an action.

II. The liability bet

The administration’s alternative to new rules is old ones. The Treasury Secretary told Congress in September that creators should be liable for what they build, and warned against granting labs any liability shield (source). The FTC chair argued that product liability and consumer protection law have adapted to every new technology for centuries, and that agents are tools whose instructors answer for them (source). The Director of National Intelligence made the same case on air (source).

The strongest version of that case deserves a hearing. Liability is technology-neutral, so the next model cannot outdate it. It avoids licensing regimes that incumbents can capture, the worry Andrew Ng and Yann LeCun have pressed for years. And courts are already biting: a federal judge let product claims against a chatbot maker proceed, leading to settlements in early 2026 (source); about a dozen wrongful-death suits now face one lab (source); a state attorney general has asked a court to halt a lab’s frontier development (source).

Yet the bet fails in four places.

  1. The clock problem. Litigation takes years; capability doubles in months. Legal scholars now argue that delay itself tilts outcomes towards whatever the industry has already built (source).
  2. The catastrophe problem. Liability works when the defendant can pay. For a true catastrophe no balance sheet is large enough, so the deterrent is illusory precisely where it matters most. Gabriel Weil’s answer, punitive damages for near-misses and insurance mandates scaled to dangerous capability, concedes the point: liability must be redesigned by statute in advance to work at all (source).
  3. The attribution problem. The main US anti-hacking law requires intent, which is hard to show when an agent acts on its own, and it is unclear whether the model’s builder or its deployer is to blame. Of the Hugging Face breach, Weil observed that no one could be liable under current law (source). The administration’s own March framework would limit developers’ liability for third parties’ misuse, the opposite of the Treasury Secretary’s line (source).
  4. The insurance problem. Liability regimes lean on insurers to price risk. Instead, major insurers have sought permission to exclude AI liabilities (source), standard general-liability forms now carry optional generative-AI exclusions (source), and none of the leading labs points to catastrophic-risk cover (source). The market that was meant to do the regulating is stepping back.

What the panel says. Timnit Gebru agrees that existing law should bite, and says the lab behind the breach could have been held liable (source). Mustafa Suleyman wants AI treated as commercial software under product-liability standards (source). Yuval Noah Harari notes that prison, the deterrent executives fear most, means nothing to an algorithm (source). Andrew Ng and Fei-Fei Li dissent: making developers liable for others’ misuse, they argue, chills open research.

Lawmakers are already writing the patch. California’s AB 316 bars the “the AI did it on its own” defence, and the first lawsuit over the agent breach relies on it (source). A bipartisan Senate bill would attach criminal and civil liability to agent hacking (source); a House draft would ease suits against developers (source); model bills would treat frontier models as products (source). The EU’s revised Product Liability Directive brings strict liability for software from December 2026. Liability is being rebuilt by statute because the common law alone cannot carry it.

The deeper problem is the crumple zone. When an agent acts and no human could have stopped it in time, liability lands on whoever is nearest: the deployer, the operator, the person who signed off. That is a moral crumple zone, accountability without control. Liability tells us who pays; it cannot tell the agent no. On the enforceability test, liability is an observation layer at societal scale: it prices harm after the fact and refuses nothing.

Liability is the bill. Governance is the brake.

III. No tort for a frozen workforce

The leader’s warning had two halves: a cataclysm, or a transformed economy. Liability misses the slow harm entirely. Courts compensate identifiable victims of identifiable wrongs. There is no tort for a frozen workforce: no plaintiff when a graduate cohort is never hired, no defendant when output rises while wages and roles stall, what I have called Ghost GDP.

Employment for 22 to 25-year-olds in the most AI-exposed roles fell 3.8% year on year by April, and more than 200 economists, including Nobel laureates, have called for policy action now (source). Daron Acemoglu, David Autor and Simon Johnson propose steering AI towards new tasks through tax, antitrust and training policy (source). Distribution is a governance problem that no clock of liability will ever reach.

Some harms have no plaintiff. They still need a policy.

IV. A policymaker’s toolkit

No single instrument covers all three clocks, so the real question is the combination. Here is the menu as it stands in October 2026, scored on the only question that matters at execution time.

InstrumentClockLive exampleWhat it fixesWhere it failsCan it say no?
If-then commitmentsBeforeLab safety frameworks (source)Ties action to evidence of dangerVoluntary; pause clauses softened in 2026; frameworks score a median 18% in one review (source)Only if honoured
Licensing and registrationBeforeProposed by Hinton and Russell; registry fee in New York’s amended lawVisibility of what existsCompute thresholds erode; a registry gives sight, not controlAt launch only
Mandated third-party auditBeforeIllinois, the first state audit mandate, from 2028 (source); assurance levels (source)Independent check on self-reported claimsAudits test compliance with the lab’s own framework; auditors are scarceNo
Regulatory sandboxesBeforeEU member-state sandboxes, deadline pushed to 2027 (source)Learning under supervisionThin evidence; risk of legitimacy theatreNo
Licensed private regulatorsBefore and duringRegulatory markets (source)Regulatory capacity at industry speedFew frontier firms; capture riskDepends on design
Runtime checkpointDuringSingapore’s runtime safeguards for agentic finance (source)Refuses an unauthorised action before it executesVoluntary; probabilistic controls creep into the kernelYes
Agent identity and authorisationDuringUS agent standards initiative (source)Every action traceable to an accountable humanStatic least-privilege fits agents poorlyPartly
Compute controls and hardware verificationBefore and duringChip export rules (source); hardware feasibility taxonomy (source)Limits who can train at the frontierSmuggling; key mechanisms years from readyAt the chip, not the action
Incident reportingAfterCalifornia 15 days, New York 72 hours, OECD common format (source)Shared learning from failuresSelf-reported; deadlines divergeNo
Statutory liabilityAfterCalifornia AB 316; EU Product Liability Directive from Dec 2026Removes the “AI did it” defenceSlow; no one left to pay for catastropheNo
Mandatory insuranceBefore and afterInsurance-as-regulation proposals (source); agent certification plus coverPuts a price on risk and a private inspector on siteInsurers currently excluding AI (source)Indirectly, through underwriting
Safe harboursAfterIllinois disclosure-for-immunity bill (failed); certification-for-safe-harbour (source)Rewards good practiceShields paperwork, not behaviourNo
International verificationBeforeSept 2026 call for an international verification body (source); UN scientific panelCross-border trustUS and China absent; no enforcementNo

Read down the last column and the pattern is stark. Of thirteen instruments, one reliably refuses an action at the moment it would cause harm, and it barely features in Washington’s debate.

The analogies indict the proposals. Lab leaders reach for the FAA, FINRA and the IAEA as models. Yet each of those institutions draws its real power from runtime supervision of conduct: air traffic control, trade surveillance, on-site inspection. Each proposal borrows only the licensing fragment. The analogy, taken seriously, argues for the middle clock.

A better bargain: the earned safe harbour. The administration wants to avoid heavy rules; the labs want protection from ruinous suits; the public wants a brake. One trade satisfies all three. Offer a liability safe harbour only to deployers whose agents run behind a verified runtime checkpoint: per-action authorisation, a tamper-evident audit trail the agent cannot write to, and an independent attestation that the checkpoint can refuse. No checkpoint, full strict liability. Illinois tried to shield firms that published documents and failed; this would shield firms that can prove their systems can say no. It turns liability from a bill into an incentive to build the brake.

Do not reward the paperwork. Reward the refusal.

V. Three jurisdictions, three clocks

The world’s three regulatory models now map neatly onto the three clocks.

The United States is betting on the third clock. Washington relies on existing liability law, a voluntary accord and a task force partly charged with preventing overregulation, while pressing to preempt state rules. The states are filling the gap regardless: California and New York mandate incident reporting, and Illinois has become the first state to require independent audits of frontier developers.

The European Union is rebuilding the third clock by statute. It withdrew its dedicated AI liability directive in 2025 but extended strict product liability to software and AI from December 2026, with presumptions of defect and causation that shift the burden of proof. It has also delayed most high-risk obligations to 2027 and 2028. Europe’s bet is that a well-designed bill arrives faster than a lawsuit.

Singapore has built the middle clock, and then placed it outside the law. Its agentic AI governance framework separates an agent’s authority from its autonomy and names orchestration drift. Its financial regulator’s runtime safeguards put a checkpoint between every agent decision and its execution, with four dispositions: deny, escalate, execute, observe. Its legal-responsibility paper concludes that agents are not legal persons and that responsibility should track control and information (source). Yet the runtime safeguards are explicitly not supervisory guidance, and deterministic rule-based logic is excluded from the regulator’s own definition of AI. The only instrument that can refuse an action sits outside the supervisory perimeter twice over. Put bluntly: the only thing that can say no is not legally AI.

That is not a criticism of Singapore so much as a map of the next move for every jurisdiction. The country that brings its middle clock inside the perimeter, and ties liability relief to it, will have written the first complete governance stack for agents.

Every jurisdiction has a clock it trusts. None yet has all three.

VI. A minimum viable stack

For a policymaker who must act this year, the toolkit reduces to five moves, one for each gap the liability bet leaves open.

  1. Close the attribution gap by statute: no “the AI acted on its own” defence, and a clear allocation between developer and deployer that tracks control.
  2. Price the catastrophe in advance: mandatory cover scaled to dangerous capability, so the insurer becomes an inspector rather than an exit.
  3. Mandate the middle clock for high-stakes agents: a runtime checkpoint with per-action authorisation for agents that can move money, touch infrastructure or act on other systems.
  4. Verify the checkpoint, not the paperwork: independent attestation that the control can refuse, tested against live trajectories, not policy documents.
  5. Earn the safe harbour at runtime: liability relief only for deployers who pass the first four, and harmonised incident reporting for everyone.

None of this requires a new superagency, and none of it is anti-innovation. It is Long-AND, not Short-OR. The lawsuit will still come; the point is to make it rare.

Liability tells us who pays. Only governance decides whether anyone has to.

VII. Notes and sources

Leave a Reply