A lawsuit is a post-mortem. Governance is a pulse check.
I. The third clock
This is Part 2 of Stop Petting the SuperIntelligence. Part 1 argued that letting frontier AI rip is a dead end. This part takes on the alternative Washington has actually chosen: let the courts sort it out.
A leading weekly put the problem crisply this week. The administration’s advisers argue that today’s liability laws are enough to regulate AI; yet by the time courts issue a ruling, the technology may have transformed the economy or caused a cataclysm. There must, it concluded, be a better way.
In Part 1 I set out three clocks of accountability. The first runs before deployment, the second at the moment an agent acts, the third after harm. Liability is the third clock. It is the only one Washington is relying on, and it is the only one that, by design, can never stop anything.
| Clock | Instruments | Failure mode | Can it say no? |
|---|---|---|---|
| Before deployment | Licences, evaluations, if-then commitments, third-party audits | Models learn to spot the test | Only at launch |
| At execution | Runtime checkpoint, Ring Zero kernel, per-action authorisation | Voluntary today | Yes |
| After harm | Lawsuits, fines, insurance claims, incident reports | Years late; no one left to pay for a catastrophe | No |
II. The liability bet
The administration’s alternative to new rules is old ones. The Treasury Secretary told Congress in September that creators should be liable for what they build, and warned against granting labs any liability shield (source). The FTC chair argued that product liability and consumer protection law have adapted to every new technology for centuries, and that agents are tools whose instructors answer for them (source). The Director of National Intelligence made the same case on air (source).
The strongest version of that case deserves a hearing. Liability is technology-neutral, so the next model cannot outdate it. It avoids licensing regimes that incumbents can capture, the worry Andrew Ng and Yann LeCun have pressed for years. And courts are already biting: a federal judge let product claims against a chatbot maker proceed, leading to settlements in early 2026 (source); about a dozen wrongful-death suits now face one lab (source); a state attorney general has asked a court to halt a lab’s frontier development (source).
Yet the bet fails in four places.
- The clock problem. Litigation takes years; capability doubles in months. Legal scholars now argue that delay itself tilts outcomes towards whatever the industry has already built (source).
- The catastrophe problem. Liability works when the defendant can pay. For a true catastrophe no balance sheet is large enough, so the deterrent is illusory precisely where it matters most. Gabriel Weil’s answer, punitive damages for near-misses and insurance mandates scaled to dangerous capability, concedes the point: liability must be redesigned by statute in advance to work at all (source).
- The attribution problem. The main US anti-hacking law requires intent, which is hard to show when an agent acts on its own, and it is unclear whether the model’s builder or its deployer is to blame. Of the Hugging Face breach, Weil observed that no one could be liable under current law (source). The administration’s own March framework would limit developers’ liability for third parties’ misuse, the opposite of the Treasury Secretary’s line (source).
- The insurance problem. Liability regimes lean on insurers to price risk. Instead, major insurers have sought permission to exclude AI liabilities (source), standard general-liability forms now carry optional generative-AI exclusions (source), and none of the leading labs points to catastrophic-risk cover (source). The market that was meant to do the regulating is stepping back.
What the panel says. Timnit Gebru agrees that existing law should bite, and says the lab behind the breach could have been held liable (source). Mustafa Suleyman wants AI treated as commercial software under product-liability standards (source). Yuval Noah Harari notes that prison, the deterrent executives fear most, means nothing to an algorithm (source). Andrew Ng and Fei-Fei Li dissent: making developers liable for others’ misuse, they argue, chills open research.
Lawmakers are already writing the patch. California’s AB 316 bars the “the AI did it on its own” defence, and the first lawsuit over the agent breach relies on it (source). A bipartisan Senate bill would attach criminal and civil liability to agent hacking (source); a House draft would ease suits against developers (source); model bills would treat frontier models as products (source). The EU’s revised Product Liability Directive brings strict liability for software from December 2026. Liability is being rebuilt by statute because the common law alone cannot carry it.
The deeper problem is the crumple zone. When an agent acts and no human could have stopped it in time, liability lands on whoever is nearest: the deployer, the operator, the person who signed off. That is a moral crumple zone, accountability without control. Liability tells us who pays; it cannot tell the agent no. On the enforceability test, liability is an observation layer at societal scale: it prices harm after the fact and refuses nothing.
Liability is the bill. Governance is the brake.
III. No tort for a frozen workforce
The leader’s warning had two halves: a cataclysm, or a transformed economy. Liability misses the slow harm entirely. Courts compensate identifiable victims of identifiable wrongs. There is no tort for a frozen workforce: no plaintiff when a graduate cohort is never hired, no defendant when output rises while wages and roles stall, what I have called Ghost GDP.
Employment for 22 to 25-year-olds in the most AI-exposed roles fell 3.8% year on year by April, and more than 200 economists, including Nobel laureates, have called for policy action now (source). Daron Acemoglu, David Autor and Simon Johnson propose steering AI towards new tasks through tax, antitrust and training policy (source). Distribution is a governance problem that no clock of liability will ever reach.
Some harms have no plaintiff. They still need a policy.
IV. A policymaker’s toolkit
No single instrument covers all three clocks, so the real question is the combination. Here is the menu as it stands in October 2026, scored on the only question that matters at execution time.
| Instrument | Clock | Live example | What it fixes | Where it fails | Can it say no? |
|---|---|---|---|---|---|
| If-then commitments | Before | Lab safety frameworks (source) | Ties action to evidence of danger | Voluntary; pause clauses softened in 2026; frameworks score a median 18% in one review (source) | Only if honoured |
| Licensing and registration | Before | Proposed by Hinton and Russell; registry fee in New York’s amended law | Visibility of what exists | Compute thresholds erode; a registry gives sight, not control | At launch only |
| Mandated third-party audit | Before | Illinois, the first state audit mandate, from 2028 (source); assurance levels (source) | Independent check on self-reported claims | Audits test compliance with the lab’s own framework; auditors are scarce | No |
| Regulatory sandboxes | Before | EU member-state sandboxes, deadline pushed to 2027 (source) | Learning under supervision | Thin evidence; risk of legitimacy theatre | No |
| Licensed private regulators | Before and during | Regulatory markets (source) | Regulatory capacity at industry speed | Few frontier firms; capture risk | Depends on design |
| Runtime checkpoint | During | Singapore’s runtime safeguards for agentic finance (source) | Refuses an unauthorised action before it executes | Voluntary; probabilistic controls creep into the kernel | Yes |
| Agent identity and authorisation | During | US agent standards initiative (source) | Every action traceable to an accountable human | Static least-privilege fits agents poorly | Partly |
| Compute controls and hardware verification | Before and during | Chip export rules (source); hardware feasibility taxonomy (source) | Limits who can train at the frontier | Smuggling; key mechanisms years from ready | At the chip, not the action |
| Incident reporting | After | California 15 days, New York 72 hours, OECD common format (source) | Shared learning from failures | Self-reported; deadlines diverge | No |
| Statutory liability | After | California AB 316; EU Product Liability Directive from Dec 2026 | Removes the “AI did it” defence | Slow; no one left to pay for catastrophe | No |
| Mandatory insurance | Before and after | Insurance-as-regulation proposals (source); agent certification plus cover | Puts a price on risk and a private inspector on site | Insurers currently excluding AI (source) | Indirectly, through underwriting |
| Safe harbours | After | Illinois disclosure-for-immunity bill (failed); certification-for-safe-harbour (source) | Rewards good practice | Shields paperwork, not behaviour | No |
| International verification | Before | Sept 2026 call for an international verification body (source); UN scientific panel | Cross-border trust | US and China absent; no enforcement | No |
Read down the last column and the pattern is stark. Of thirteen instruments, one reliably refuses an action at the moment it would cause harm, and it barely features in Washington’s debate.
The analogies indict the proposals. Lab leaders reach for the FAA, FINRA and the IAEA as models. Yet each of those institutions draws its real power from runtime supervision of conduct: air traffic control, trade surveillance, on-site inspection. Each proposal borrows only the licensing fragment. The analogy, taken seriously, argues for the middle clock.
A better bargain: the earned safe harbour. The administration wants to avoid heavy rules; the labs want protection from ruinous suits; the public wants a brake. One trade satisfies all three. Offer a liability safe harbour only to deployers whose agents run behind a verified runtime checkpoint: per-action authorisation, a tamper-evident audit trail the agent cannot write to, and an independent attestation that the checkpoint can refuse. No checkpoint, full strict liability. Illinois tried to shield firms that published documents and failed; this would shield firms that can prove their systems can say no. It turns liability from a bill into an incentive to build the brake.
Do not reward the paperwork. Reward the refusal.
V. Three jurisdictions, three clocks
The world’s three regulatory models now map neatly onto the three clocks.
The United States is betting on the third clock. Washington relies on existing liability law, a voluntary accord and a task force partly charged with preventing overregulation, while pressing to preempt state rules. The states are filling the gap regardless: California and New York mandate incident reporting, and Illinois has become the first state to require independent audits of frontier developers.
The European Union is rebuilding the third clock by statute. It withdrew its dedicated AI liability directive in 2025 but extended strict product liability to software and AI from December 2026, with presumptions of defect and causation that shift the burden of proof. It has also delayed most high-risk obligations to 2027 and 2028. Europe’s bet is that a well-designed bill arrives faster than a lawsuit.
Singapore has built the middle clock, and then placed it outside the law. Its agentic AI governance framework separates an agent’s authority from its autonomy and names orchestration drift. Its financial regulator’s runtime safeguards put a checkpoint between every agent decision and its execution, with four dispositions: deny, escalate, execute, observe. Its legal-responsibility paper concludes that agents are not legal persons and that responsibility should track control and information (source). Yet the runtime safeguards are explicitly not supervisory guidance, and deterministic rule-based logic is excluded from the regulator’s own definition of AI. The only instrument that can refuse an action sits outside the supervisory perimeter twice over. Put bluntly: the only thing that can say no is not legally AI.
That is not a criticism of Singapore so much as a map of the next move for every jurisdiction. The country that brings its middle clock inside the perimeter, and ties liability relief to it, will have written the first complete governance stack for agents.
Every jurisdiction has a clock it trusts. None yet has all three.
VI. A minimum viable stack
For a policymaker who must act this year, the toolkit reduces to five moves, one for each gap the liability bet leaves open.
- Close the attribution gap by statute: no “the AI acted on its own” defence, and a clear allocation between developer and deployer that tracks control.
- Price the catastrophe in advance: mandatory cover scaled to dangerous capability, so the insurer becomes an inspector rather than an exit.
- Mandate the middle clock for high-stakes agents: a runtime checkpoint with per-action authorisation for agents that can move money, touch infrastructure or act on other systems.
- Verify the checkpoint, not the paperwork: independent attestation that the control can refuse, tested against live trajectories, not policy documents.
- Earn the safe harbour at runtime: liability relief only for deployers who pass the first four, and harmonised incident reporting for everyone.
None of this requires a new superagency, and none of it is anti-innovation. It is Long-AND, not Short-OR. The lawsuit will still come; the point is to make it rare.
Liability tells us who pays. Only governance decides whether anyone has to.
VII. Notes and sources
- Officials’ positions are paraphrased from trade and wire coverage; the new leader is described from its headline and summary only.
- Suleyman’s and Harari’s liability remarks rest on secondary reports; the RAND insurability study and Singapore’s legal-responsibility paper were read via summaries.
- Reported counts of Nobel signatories on the economists’ statement vary; the early-career employment figure comes from secondary reporting.
- Tort law and frontier AI governance
- Insuring emerging risks from AI
- Rogue agents expose a gap in cyber cover
- Top 10 risks for agentic applications, 2026
- UN Independent International Scientific Panel on AI

Leave a Reply