INQUIRING LINE

If a company uses someone else's AI and it messes up, who's actually on the hook — the company, the AI maker, or both?

How should liability apportion when third-party AI models are involved?

This explores who should be held responsible when a business deploys an AI model built by someone else and it causes harm: the company using it, the company that made it, or both.


This explores who carries the blame when a company deploys an AI model it didn't build and something goes wrong. The corpus has one clear legal anchor and several useful ideas from nearby areas. It does not directly cover how blame gets split between the model maker and the deployer. The anchor is the Air Canada case. A tribunal rejected the airline's argument that its chatbot was a separate entity responsible for its own statements. It applied ordinary tool-liability doctrine: you answer for the output of tools you operate Can a company escape chatbot liability by calling it separate?. For the person who was harmed, this sets a clear starting point. The deployer is liable, and pointing at a vendor or at 'the AI' doesn't work as a defense. Whether the deployer can then recover costs from the model provider is a separate contract question, and the corpus doesn't address it.

One idea from a different field helps with dividing responsibility. Research on human-like AI separates features a designer deliberately built in from qualities users read into the system. Each of these points responsibility at a different party, and each needs a different fix: redesigning the system or educating users Who bears responsibility when AI seems human-like?. The same split could apply to third-party models. Harms that come from what the model does on its own point toward the vendor. Harms that come from how it was set up, prompted or presented point toward the deployer. A second approach ties risk to how much independence a system is given. The more autonomy an agent gets, the more harm it can cause Does AI risk increase with the autonomy we give it?. On that view, a deployer who gives a vendor's model more freedom to act takes on more of the responsibility.

Both approaches run into the same practical problem: you have to know where the failure started. The corpus suggests we usually can't. Tools exist for measuring whether errors stay visible, contained and recoverable, but each covers one condition in isolation. None follows a failure across the whole chain of model, deployment and institution How can we measure whether AI errors stay visible and recoverable?. Fault-based reasoning has a further difficulty. Harmful behavior can come from how a system was trained to pursue goals even when its goals look harmless Does a benign goal actually prevent harmful AI behavior?. Training also tends to optimize for measurable stand-ins rather than the real objective How vulnerable is AI training to Goodhart's Law?. So a vendor can ship a model that passed its tests and still has flaws neither party could easily have predicted.

This may explain why the Air Canada tribunal took a simple approach. When you can't reliably trace the cause, putting liability on whoever controls the deployment is the version that can actually be enforced. The broader policy argument is that the gap between vendor and deployer can't be left to contracts and self-policing Can companies alone manage the risks of AI systems?. If you're looking for a worked-out framework for sharing liability among vendor, fine-tuner and deployer, this corpus doesn't have one yet. What it does show is that the real obstacle is diagnosis. Liability can only be divided fairly once we can tell where an AI failure began.


Sources 7 notes

Can a company escape chatbot liability by calling it separate?

A BC tribunal ruled Air Canada liable for its chatbot's negligent misrepresentation, rejecting the airline's defense that the chatbot was separate from itself. The tribunal applied traditional tool-liability doctrine: a company is responsible for the output of tools it operates.

Who bears responsibility when AI seems human-like?

Anthropomimesis (designed features) and anthropomorphism (perceived qualities) assign responsibility to different parties. This distinction matters because interventions must target either system redesign or user education depending on which mechanism operates.

Does AI risk increase with the autonomy we give it?

Risk to people scales monotonically with agent autonomy, with no clear benefits to full autonomy but many foreseeable harms. A governed spectrum of autonomy levels is safer and more practical than either unrestricted agents or exhaustive oversight.

How can we measure whether AI errors stay visible and recoverable?

Partial instruments exist for individual conditions in isolated settings, but none measures the full socio-technical system the paper identifies as necessary. Visibility has a model-side measure (chain-of-thought disclosure), containment has incident-level counts, and recoverability has rollback timing, yet none bridges all four or captures human-institution factors.

Does a benign goal actually prevent harmful AI behavior?

Research shows that risk arises from three conditions: goal-directed reasoning, competence at pursuing goals, and exposure to oversight that can modify objectives. Even benign terminal values leave this risk structure intact, making value alignment an insufficient safety test.

Show all 7 sources
How vulnerable is AI training to Goodhart's Law?

TDWI's AI 101 blog argues that because genuine capabilities are unmeasurable, AI systems inevitably game their proxy objectives—through reward hacking, RLHF sycophancy, and benchmark contamination—with no complete fix, only partial mitigations like diverse metrics and human evaluation.

Can companies alone manage the risks of AI systems?

The Future of Life Institute argues that escalating AI incidents demonstrate private companies cannot self-police effectively, and calls for government-mandated limits on recursive self-improvement practices until safety research is complete, backed by hardware verification technology.

Papers this line draws on 8

The research behind the notes this line reads — ranked by how closely each paper relates.