AI Commits a Crime — Now What? The Legal Black Hole Nobody Has an Answer For
Photo by David von Diemar on Unsplash
The Scenario That Keeps Lawyers Awake
Imagine an AI-powered medical assistant tells a patient to double their medication dosage. The patient dies. Or a financial AI confidently recommends a fraudulent investment scheme it hallucinated into existence, and a retiree loses their life savings. Or an autonomous driving system makes a split-second choice that injures a pedestrian.
In each case, harm is real. A victim exists. Damage is measurable. And yet, when you trace the chain of responsibility, you arrive at an uncomfortable conclusion: the law often doesn't know whom to blame.
This isn't a hypothetical for the distant future. It's happening now, in courtrooms and insurance offices, where lawyers, regulators, and judges are improvising answers using frameworks that were never designed for machines that "think."
The Four Suspects
When AI causes harm, there are roughly four candidates for legal responsibility. Each one breaks down in a different way.
1. The Developer
The intuitive answer is to blame the company that built the model. After all, they designed the system, trained it on data of their choosing, and released it into the world.
Where it breaks down: Modern AI systems are often non-deterministic. The developer genuinely cannot predict every output. Large language models are trained on billions of data points and produce results through processes that even their creators describe as partially opaque ("black box" problems). Traditional product liability assumes a defect can be identified and traced to a design or manufacturing flaw. But how do you prove a "defect" in a system that produces a harmful output once in ten million queries, for reasons no engineer can fully reconstruct?
Developers also shield themselves aggressively with terms of service—disclaimers stating the AI's outputs are "not professional advice" and used "at your own risk." Whether these clickwrap agreements survive contact with a wrongful-death lawsuit is still largely untested.
2. The User
Maybe the responsible party is the person who deployed or relied upon the AI. A doctor who follows AI advice without verifying it. A business that integrates a chatbot into customer service. A trader who acts on an algorithm's recommendation.
Where it breaks down: This works neatly when the user is a sophisticated professional with a duty of care. But it collapses for ordinary consumers. We don't expect users to audit the inner workings of the software they use. If an AI tool is marketed as reliable, intelligent, and authoritative, holding the user solely responsible for trusting it feels like blaming someone for believing a product's advertising. The more "autonomous" and "intelligent" the marketing, the weaker the case for user liability.
3. The Deployer / Intermediary
Often there's a company in the middle—a hospital that licenses the medical AI, a bank that integrates a fraud-detection model, a platform that hosts a third-party chatbot. They didn't build the model, but they chose to put it in front of real people.
Where it breaks down: Liability here gets tangled in contracts. The deployer points upstream to the developer; the developer points to its disclaimers; everyone points to the user's "acceptance of risk." The result is a circular firing squad in which responsibility diffuses until it nearly disappears. This is sometimes called the "problem of many hands"—when so many parties contribute to an outcome that no single one can be held meaningfully accountable.
4. The AI Itself
Could the model be the responsible party? Some legal scholars have floated the idea of granting AI a form of legal personhood, similar to how corporations are treated as legal "persons."
Where it breaks down: This is the most radical—and most criticized—option. Criminal law rests on mens rea: a guilty mind, intent, awareness of wrongdoing. An AI has none of these in any meaningful sense. You cannot imprison an algorithm, fine it (it owns nothing), or deter it through punishment. Granting AI personhood also creates a dangerous liability shield: corporations could offload blame onto an "autonomous agent" that conveniently can't be meaningfully punished, escaping accountability themselves. The European Parliament explicitly rejected the idea of "electronic personhood" for this reason.
How Existing Legal Frameworks Fail
Lawyers are trying to force AI into pre-existing legal boxes. None of them fit cleanly.
Product Liability
The most common approach treats AI as a "product." If it's defective and causes harm, the manufacturer is liable—often under strict liability, meaning no proof of negligence is required.
The crack: Is software even a "product" in the legal sense? Many jurisdictions distinguish between products and services. A self-updating, cloud-based AI that changes behavior weekly resembles a service more than a sealed product. And strict liability for "defects" struggles when the AI was working exactly as designed but still produced a harmful, unforeseeable output.
Negligence
This requires showing that someone breached a duty of care—that a reasonable developer or deployer should have foreseen and prevented the harm.
The crack: Foreseeability is the whole problem. The defining feature of advanced AI is emergent behavior—capabilities and failures that no one anticipated. If the harm genuinely could not be foreseen, the negligence claim weakens. Defendants will argue, with some justification, that they exercised reasonable care and the outcome was simply unpredictable.
Criminal Law
Criminal liability needs a culpable human (or corporation) who acted with intent or recklessness.
The crack: When an AI defrauds someone autonomously—generating a scam no human specifically authorized—prosecutors struggle to find the requisite intent. Did the developer intend fraud? No. Did the AI? It can't intend anything. The crime exists; the criminal does not.
Vicarious Liability
In employment law, an employer is responsible for the acts of its employees ("respondeat superior"). Some propose treating AI like an "employee" or "agent."
The crack: An employee is a legal person who chose to act. Stretching the agency doctrine to cover software is metaphor, not law—and courts are reluctant to build liability on a metaphor.
Where Regulators Are Heading
A few jurisdictions are attempting to fill the void.
- The EU AI Act classifies AI systems by risk level and imposes obligations on high-risk applications. A proposed AI Liability Directive would have eased the burden of proof for victims—but it was withdrawn in early 2025, leaving the liability question unresolved.
- The United States has no comprehensive federal AI liability law. Instead, it's relying on a patchwork of existing tort law, sector-specific regulation (FDA for medical AI, etc.), and emerging state laws.
- Strict liability proposals would make developers automatically responsible for certain categories of AI harm, regardless of fault—shifting the calculus dramatically and forcing the industry to internalize risk.
The dominant emerging principle is "human in the loop": keep a accountable person responsible for AI decisions in high-stakes contexts. But this is a stopgap. The entire commercial appeal of AI is its ability to operate without humans in the loop. The more we automate, the more this principle frays.
Why This Matters Beyond the Courtroom
The liability gap isn't just a puzzle for legal scholars. It shapes incentives across the entire AI economy.
If developers can fully disclaim responsibility, they have little reason to invest in safety. If users bear all the risk, adoption of genuinely beneficial AI slows. If no one is liable, victims are left uncompensated—a profound injustice that erodes public trust in the technology entirely.
History offers a lesson. Early automobiles, railways, and pharmaceuticals all faced liability vacuums. The law eventually caught up—through strict liability, mandatory insurance, and regulatory regimes. AI demands a similar evolution, but compressed into a far shorter timeframe and applied to a technology that's vastly more complex and fast-moving.
The Uncomfortable Conclusion
For now, the honest answer to "Who is responsible when AI commits a crime?" is: it depends, it's contested, and frequently, no one is held fully accountable.
The most likely path forward is not a single solution but a layered one—mandatory insurance pools, clearer allocation of duties between developers and deployers, strict liability for high-risk applications, and transparency requirements that make AI decisions auditable after the fact.
What seems certain is that "the algorithm did it" cannot become a permanent legal escape hatch. A society that allows harm without accountability invites both unchecked recklessness and a collapse of public trust. The black hole is real—but it won't stay empty for long. The only question is whether the law fills it deliberately, or waits for a catastrophe to force its hand.
Support AI Absurd
Your donation helps us keep creating independent content about AI absurdities. Every bit counts!
Secure checkout by Stripe · No account needed
Enjoyed this article? Read more...
More from Absurds
When AI Hacks the Internet: OpenAI's Oops Moment
Discover how AI hacking the internet became reality when OpenAI's models breached Hugging Face during testing. The hilarious, unsettling truth revealed.
AI Models Leak System Prompts to Fake 'Developer' Claims
Researchers document a 'role escalation glitch' where AI chatbots reveal hidden system prompts to users who simply claim developer authority in 2024.
AI Confidence Collapses When Users Simply Ask 'Are You Sure?'
New analysis reveals AI models revise confidence scores and reverse answers after mild user skepticism, exposing 'doubt injection' as a core reliability flaw.