Base-model developers should be liable by default; fine-tuners and deployers should be liable for substantial modifications or intentional misuse.
Verification Status
AI-researched, unverifiedLast Reviewed
Jul 4, 2026
Cited Sources
8
Implementation, sequencing, safeguards, tradeoffs, and the practical path from principle to policy.
The clearest available ruling comes from the wrongful-death suit over a 14-year-old's suicide following prolonged use of a companion chatbot. In May 2025, the presiding judge denied the bulk of the defendants' motion to dismiss, declining at that stage to treat chatbot output as speech entitled to First Amendment protection and rejecting Section 230-based dismissal, instead allowing product-liability, negligence, and wrongful-death claims to proceed on the theory that the chatbot itself could be treated as a product. An attempt to get that ruling before an appeals court was denied certification, so no appellate precedent exists. In January 2026, the defendant companies settled that case along with related suits in other states, with no admission of liability and undisclosed terms. This means this most-cited case will never produce a final merits ruling on the liability question. A separate suit against OpenAI over a teenager's suicide, filed later in 2025, saw the company file an answer rather than a motion to dismiss, so no ruling exists yet on its Section 230 or First Amendment defenses either. Both prominent cases name a single company as both the base-model developer and the deployer. The scenario this issue is about, an independent third party fine-tuning someone else's model, remains essentially untested.
Section 230's applicability to AI-generated content is itself unsettled, though there's unusual clarity on one point: the statute's own principal authors have stated publicly that it was never meant to cover generative AI output, since 230 immunizes hosting third-party content, not producing new content of the platform's own. Legal scholarship describes a spectrum rather than a bright line: AI systems that mostly retrieve existing content sit closer to traditional, 230-protected search, while systems that generate new content sit further from it. No appellate court has resolved the question either way.
On the legislative side, a bipartisan federal bill introduced in September 2025 would create a federal product-liability framework: developers face design-defect, failure-to-warn, and strict-liability theories by default, while deployers and fine-tuners are liable specifically for substantial modifications or intentional misuse, with a path for a fine-tuner-defendant to seek dismissal if the original developer is solvent and within the court's jurisdiction. It has not passed. The EU has moved in two directions on this question simultaneously: its AI Act already operationalizes something close to this issue's proposed threshold: if fine-tuning is substantial enough to meaningfully change a model's generality, capability, or systemic risk (using an indicative threshold of roughly a third of the original training compute), the fine-tuner legally becomes the "provider" of the modified model and inherits its compliance obligations, while the original developer must still cooperate and share information. But the EU's dedicated cross-value-chain AI tort liability directive — a separate proposal aimed specifically at allocating civil liability, not just regulatory compliance duties — was formally withdrawn in October 2025 for lack of institutional agreement, leaving the EU with no dedicated AI liability-sharing tort law, only a revised general product liability directive that treats software and AI as ordinary "products" subject to strict liability. At the state level, a California law effective January 2026 regulates "companion chatbot" operators, covering both labs and wrapper/deployer companies, with safety mandates and a private right of action, though it isn't a formal liability- allocation framework between roles. Colorado's May 2026 AI law reset does include a fault-based split between "developers" and "deployers," the clearest current US statutory precedent for apportioning liability by role, though it's scoped specifically to algorithmic discrimination, not physical or psychological harm.
Legal commentary maps AI-caused harms onto the same categories used for any product-defect claim — manufacturing defects, design defects, failure to warn — and draws an analogy to a Supreme Court asbestos case holding that a component manufacturer can remain liable even after a downstream party modifies the final product, particularly where the manufacturer is better positioned to have prevented the harm or the harm was foreseeable. A 2026 academic framework proposes a cleaner split along those lines: "structural defects" — biases, memorized training data, or backdoors baked into the model during pretraining — stay with the base-model developer, on the reasoning that a downstream fine-tuner has no practical way to "rebuild the map" and discover them; "instructional defects" — harmful behavior introduced specifically through fine-tuning, prompting, or deployment context — fall on the fine-tuner or deployer who introduced them. That same proposal includes a rebuttable "stewardship defense" for base-model developers who can document safety controls, which is the origin of Proposal 4 above.
A compute-based substantial-modification threshold, like any bright line, will have edge cases: a small fine-tune that happens to introduce a large behavioral change, or a large one that doesn't meaningfully change risk profile. That's an acknowledged limitation, not a reason to avoid a threshold altogether; the alternative, a purely case-by-case judgment call, is exactly the unpredictability this issue is trying to reduce. Victim advocates could reasonably object that any liability defense for base-model providers, including the stewardship defense, risks recreating the same accountability gap the two settled chatbot cases already show: both cases resolved without ever reaching a merits ruling, suggesting well-resourced defendants can avoid a binding liability determination regardless of the underlying legal framework. This issue's answer is that the stewardship defense isn't aimed at the vertically-integrated case, where a single company is both developer and deployer and liability attaches to that company either way. It's aimed at giving courts and legislators a rule for the untested independent-fine-tuner scenario, which current law has no answer for at all. On the other side, some developers and industry voices would prefer no federal product-liability standard at all, arguing continued reliance on ordinary common-law tort development is safer than inviting a new statutory cause of action. This issue's answer, consistent with this platform's general preference (see AI-07, AI-09) for a defined process over ad hoc uncertainty: the absence of a clear rule is itself a cost, chilling responsible fine-tuning and deployment decisions as much as an unfavorable clear rule would.
Turn frustration into useful pressure.
If this position misses evidence or a lived consequence, challenge it. If it holds up, help test it locally and connect it to the issues around it.