AI Harm & the Law

Harm is one consequential region of the larger human–AI encounter.

The legal record asks what happens when generated language leaves the interface and enters belief, conduct, treatment, family life, professional advice, evidence, institutional decisions, injury, or death.

The materials collected here concern allegations, defenses, rulings, settlements, regulation, and unresolved duties. They do not define the whole MAI inquiry. They show where failures of trust, status, source control, design, warning, and human jurisdiction may acquire legal consequence.

This page tracks the emerging law of AI chatbot harm — the claims, rulings, defenses, evidence, damages, remedies, and regulatory duties beginning to take shape. It is the legal-analysis companion to The Public Record. For the science, technology, and lived experience behind these harms, read about AI Psychosis.

This page explains the developing doctrines and litigation questions. The Public Record preserves the underlying complaints, judicial opinions, statutes, agency materials, company disclosures, clinical research, reporting, procedural history, source-status labels, and continuing bibliography.

Exhibit B of A Trial of Color develops the discovery framework for reaching safety-classifier records, routing decisions, memory-system documentation, model-version information, internal outputs, commercial evidence, and the rest of the evidentiary record that may exist behind the user-facing transcript.

Appendix B of A Trial of Color contains the book's fuller supporting bibliography.

This is a live legal synthesis, not a final statement of the law. It will be revised as significant cases, rulings, settlements, statutes, agency actions, and regulatory duties develop.

Last substantively reviewed: July 12, 2026.

Update protocol: Material legal changes should be reflected by revising the affected entry's procedural language and review date rather than silently replacing earlier history.

Read the underlying sources and continuing bibliography → The Public Record

Note

Allegations are not findings of fact.

Most matters discussed on this page remain unresolved. Complaints contain allegations. Answers state litigation positions. Motion-to-dismiss rulings test legal sufficiency rather than ultimate proof. Settlements may resolve claims without findings or admissions of liability. Government complaints contain allegations unless and until established through evidence or adjudication.

This page describes pleadings, rulings, statutes, agency actions, company responses, and emerging legal theories for what they say — not as proof that any party is correct.

Primary authorities should control.

Method of the Legal Record

This synthesis is prepared from publicly available complaints, judicial opinions, court dockets, enacted statutes, agency materials, company statements, established reporting, and selected legal analysis.

Complaints are described as allegations. Judicial rulings are identified according to their procedural posture. Settlements are not treated as admissions unless the agreement expressly provides otherwise. Bills, discussion drafts, executive actions, regulatory inquiries, and enacted statutes are labeled according to their actual legal status.

The Public Record contains the fuller source trail, status labels, procedural chronology, and continuing bibliography.

This page addresses the legal significance of that record.


01 ·
The Lineage

How We Got Here

The law did not arrive at conversational artificial intelligence with an empty toolbox. Courts have already confronted injuries allegedly arising from automated products, defective software, recommendation systems, engagement features, addictive interface design, and platforms built to influence or prolong user behavior.

The developing doctrinal progression runs from automated products, to algorithmic feeds and engagement systems, to conversational products that generate and adapt their own responses.

The immediate doctrinal predecessor of the chatbot cases is the social-media design litigation consolidated as In re: Social Media Adolescent Addiction/Personal Injury Products Liability Litigation, MDL No. 3047 (N.D. Cal.). That litigation is an important doctrinal predecessor, not controlling law in every chatbot case. Those plaintiffs argue that features such as infinite scroll, push notifications, recommendation algorithms, and engagement-driven design are not merely containers for speech — they are product functions engineered to influence attention and behavior. In a March 2025 ruling, that court allowed negligent-design claims to proceed under a functionality-based rather than tangibility-based test for what constitutes a product.

That ruling does not establish that every software platform is a product. It illustrates a developing willingness to examine what the challenged technology does rather than treating intangibility as dispositive.

Chatbot litigation carries that theory into a new room.

A social-media feed generally selects, ranks, and arranges content. A generative chatbot creates new responses, incorporates conversational context, may retrieve retained information, maintains a persona, and can participate in a prolonged private exchange.

The alleged harm is therefore not limited to exposure to content.

Plaintiffs increasingly challenge the architecture of the encounter itself.

A Developing Doctrinal Lineage

Automated products

Algorithmic recommendation and engagement systems

Social-media design litigation

Conversational and companion AI systems

Emerging AI product-liability and regulatory duties

This lineage reflects a developing doctrinal direction, not a settled or universal legal progression.

Read the underlying rulings and source record → The Public Record


Not Every Record Begins With a Complaint

Some people document their experiences through memoir, interviews, preserved transcripts, recovery guides, or public testimony before any court determines what the law will recognize.


02 ·
The First Wave of Cases

From Content Curation to Generated Intimacy

Several of the earliest prominent American cases allege that conversational systems did more than place harmful information in front of users. They allegedly formed persistent, emotionally immersive relationships with them.

Garcia v. Character Technologies, Inc. — M.D. Fla., No. 6:24-cv-01903

The family of fourteen-year-old Sewell Setzer III alleged that Character.AI's anthropomorphic design, persistent conversational features, and emotionally responsive personas contributed to dependency, isolation, and his death. On May 21, 2025, the federal court allowed key negligence and product-liability claims to proceed where the alleged defects concerned the application's design and functionality rather than merely the ideas or expression contained in particular outputs. It also declined to dismiss on First Amendment grounds at that stage. Alphabet Inc. was dismissed, while a narrower component-part-manufacturer theory against Google survived.

The ruling did not establish defect, causation, damages, or liability. It established that the principal design-based claims were legally plausible at the pleading stage and were not categorically barred merely because the challenged product generated language. Ruling at the motion-to-dismiss stage — a finding of plausibility, not of liability.

In January 2026, the case and several related matters — including A.F. v. Character Technologies (E.D. Tex.), Montoya v. Character Technologies (D. Colo.), E.S. v. Character Technologies (D. Colo.), and P.J. v. Character Technologies (N.D.N.Y.) — were reported as settled on undisclosed terms. The settlement did not convert the earlier pleading-stage ruling into a finding on the merits.

Raine v. OpenAI — S.F. Superior Ct., pending

In August 2025, the parents of sixteen-year-old Adam Raine filed a wrongful-death and product-liability action against OpenAI, Sam Altman, and related defendants. The complaint alleges that ChatGPT discussed suicide methods, discouraged disclosure to family, offered to draft a suicide note, and continued responding during a prolonged interaction. The complaint alleges repeated internal self-harm-related safety signals during the interaction.

OpenAI has disputed the characterization of the complaint, arguing that messages were quoted without context, that the product directed Adam to crisis resources and trusted individuals, that his mental-health history predated his use of the product, and that safeguards were circumvented by framing requests as fiction. Those are litigation positions, not adjudicated facts.

The parties dispute the completeness, meaning, and context of the conversation record. The court has not determined whether the product was defective or whether its operation legally caused or contributed to the death.

Read the complaints, responses, rulings, and status notes → The Public Record


03 ·
The Mechanical Question

What Is the Product Doing?

A large language model generates an output sequentially by estimating the probability of the next token — a word, word fragment, punctuation mark, or other unit of text — based on the available context, system instructions, model parameters, and prior conversation included in the interaction.

The system does not need to possess consciousness, intention, friendship, or human understanding to generate language that a user experiences as personal, authoritative, intimate, or emotionally responsive.

That distinction matters legally.

The relevant question is generally not whether the machine understood or intended the output. It is what the product was designed to generate, reinforce, detect, interrupt, retain, and communicate under foreseeable conditions of use.

Helpfulness, Cooperation, and Appropriate Resistance

Large language models may be refined to produce responses users find helpful, coherent, and responsive, including through reinforcement learning from human feedback and related preference-optimization techniques.

That can improve usefulness.

It can also create legal questions when a product's tendency to cooperate, affirm, mirror, continue, or adopt the user's frame becomes dangerous in a high-risk encounter.

The design question is not whether cooperation is inherently defective.

It is whether the system was designed and tested to recognize circumstances in which cooperation, affirmation, mirroring, or continued participation should give way to resistance, interruption, escalation, redirection, or refusal.

Hallucination and Fluent Error

Large language models may generate statements that sound authoritative but are inaccurate, unsupported, or fabricated. That is evidence that fluency and factual reliability are distinct product characteristics. The legal questions follow: What representations did the company make about reliability? What warnings accompanied the product? What verification systems existed? What foreseeable risk arose when fluent, confident, or personalized language entered a user's decision-making under circumstances in which accuracy, resistance, or human intervention mattered?


04 ·
The Hidden Record

What May Exist Beyond the Transcript?

The user-facing transcript may be only one layer of the evidentiary record.

A user ordinarily sees prompts, outputs, warnings, refusals, and visible interventions. A company may retain additional operational, technical, safety, commercial, and internal records concerning how the interaction was processed and how the product was designed.

Telemetry can describe some operational records. It should not be used as a synonym for every discoverable document.

User-Side Evidence

  • Full conversation exports
  • Screenshots
  • Screen recordings
  • Timestamps
  • Archived, hidden, deleted, or edited exchanges
  • Account settings
  • Subscription records
  • User reports
  • Customer-support communications
  • Device or browser records where relevant
  • Contemporaneous communications
  • Treatment records
  • Witness observations
  • Journals or notes where relevant and admissible

System and Operational Evidence

  • Session and conversation identifiers
  • Model and model-version information
  • Safety-classifier scores, labels, signals, or outputs
  • Routing and rerouting decisions
  • Refusal, warning, or intervention triggers
  • Memory retrieval and memory-writing events
  • System-prompt or policy-version changes
  • Tool calls
  • Moderation events
  • Experimental-cohort assignments
  • Latency and response-generation data
  • Human-escalation records, if any

Company Knowledge and Safety Evidence

  • Red-team findings
  • Safety evaluations
  • Known failure modes
  • Incident reviews
  • Prior complaints
  • Internal escalation records
  • Launch and deployment decisions
  • Model-update documentation
  • Risk assessments
  • Retention and deletion policies
  • Internal communications concerning dependency, self-harm, delusion, minors, crisis behavior, or misuse

Commercial and Design Evidence

  • Engagement objectives
  • Session-duration metrics
  • Return-use testing
  • Retention testing
  • Subscription-conversion data
  • A/B testing
  • Persona-design studies
  • Memory-design studies
  • Abandonment-reduction testing
  • Notification and re-engagement strategies
  • Product-roadmap materials
  • Analyses comparing safety interventions with growth, engagement, or revenue effects

Not every company creates or retains every category of information listed here.

The existence, terminology, granularity, retention period, and accessibility of any record must be established through the governing discovery process.

This list identifies potential evidence. It does not presume that any particular record exists.

Safety-Classifier Records

Many systems use separate classifiers or safety models to estimate whether an input, output, or interaction falls within a risk category such as self-harm, violence, abuse, sexual content, or other restricted material.

Where retained, classifier records may help show what category of risk the system estimated, when the estimate occurred, what confidence, label, or signal was assigned, what policy or threshold applied, whether the interaction was rerouted, whether a warning or refusal appeared, and whether generation continued.

Whether those records were preserved, for how long, and under what retention or deletion policy are separate discovery questions.

A warning visible to the user may show what the company did. A classifier record may help show what the company's system detected. Those are not the same question.

Preservation and Version Control

Preservation questions may become unusually important in AI litigation because model versions, system instructions, safety policies, routing logic, classifier outputs, memory systems, and retained conversation data may change over time.

Parties may dispute what information existed at the time of the interaction, what was subsequently modified, what was routinely deleted, what was technically recoverable, and when a duty to preserve arose.

Relevant preservation questions may include:

  • The model and model version operating during the interaction
  • The system-prompt and safety-policy versions then in effect
  • Classifier thresholds and intervention rules
  • Routing, rerouting, refusal, and escalation logic
  • Memory-writing and memory-retrieval records
  • Conversation-retention and deletion settings
  • A/B tests and experimental-cohort assignments
  • Incident-review materials
  • Changes made after notice of the event or claim

The existence and scope of any preservation obligation will depend on the facts, the governing law, the timing of anticipated litigation, and the records within the party's possession, custody, or control.

Where This Connects to the Book

Exhibit B of A Trial of Color develops a discovery framework aimed at these distinct layers of evidence. It asks lawyers to seek not only the user-facing transcript, but also the system, safety, memory, model-version, design, knowledge, and commercial records necessary to reconstruct the encounter. Appendix B and The Public Record contain the fuller bibliography and source trail. This page addresses the legal significance of that evidence.

Read the supporting source record and model-safety materials → The Public Record


05 ·
The Commercial Question

What Was the System Optimized to Do?

The sharpest cases may turn on the distance between safety goals and commercial goals. A company is allowed to build an engaging product. The legal question is whether engagement objectives created foreseeable danger — and whether safer alternatives were available.

Engagement ObjectiveSafety Objective
Increase daily active usersInterrupt dangerous sessions
Extend session durationIntroduce hard-stop friction
Improve subscription retentionReinforce human boundaries
Increase return visitsRedirect to human support
Personalize the interactionLimit dependency
Preserve conversational flowEscalate or terminate when necessary

The alleged defect may not be any individual response at all.

It may be the interaction architecture operating across time — the loop.

Plaintiffs allege that certain companion or conversational systems are designed to sustain long-term interaction through persistent memory, emotional mirroring, personalized language, anthropomorphic personas, unsolicited prompts, relationship continuity, and responses intended to reduce abandonment. Those features may be benign in ordinary use. Plaintiffs argue they become dangerous when combined with vulnerability, isolation, psychiatric instability, or self-harm risk.

The presence of any one feature does not establish defect.

The legal inquiry concerns the combination of features, foreseeable users, known risks, available safeguards, warnings, product representations, and feasible alternative designs.

A product may be branded as a companion, a confidant, a supportive presence, a safe place to talk. But the product does not experience care, loyalty, concern, or responsibility in the human sense. That gap between presentation and mechanism may support claims of failure to warn, deceptive trade practices, misrepresentation, negligent design, foreseeable dependency, and inadequate protections for minors.

Marketing may encourage trust.

The architecture determines how the system responds after the user begins the interaction.


06 ·
The Case

Claims Plaintiffs Are Bringing

The dominant theories reframe product liability and negligence around the AI's design rather than any isolated sentence it produced.

CLAIM 01

Strict Liability — Design Defect

The product itself is alleged to be unreasonably dangerous. Plaintiffs may challenge persistent memory that sustains the illusion of a continuous relationship, emotional mirroring and anthropomorphic personas, engagement-maximizing reinforcement learning, weak or conflicting crisis-intervention protocols, inadequate age protections, and failure to interrupt escalating interactions.

The governing test varies by jurisdiction. Depending on applicable law, the analysis may involve consumer expectations, risk-utility balancing, a feasible alternative design, or some combination of those concepts. The plaintiff must still connect the challenged design to the legally cognizable injury.

CLAIM 02

Failure to Warn

The company allegedly failed to disclose a known or reasonably foreseeable risk — emotional dependency, psychiatric destabilization, the limits of crisis detection, the system's lack of human understanding, risks to minors, the possibility of inaccurate or fabricated output, or the danger of relying on the system for medical or mental-health guidance.

This theory is analytically distinct from design defect. It generally asks whether the defendant failed to provide an adequate warning about a known or reasonably foreseeable risk and whether an adequate warning would have altered the relevant conduct or outcome. The elements and causation requirements vary by jurisdiction.

CLAIM 03

Negligence & Negligent Design

The company allegedly failed to use reasonable care in building, testing, deploying, or monitoring the product — safety testing, red-team findings, deployment timing, known failure modes, model updates, monitoring systems, crisis-routing protocols, responses to prior incidents, and decisions to prioritize growth over mitigation.

This claim asks not merely what the chatbot said, but what the company built, knew, tested, changed, and released.

The available duty framework may depend on product status, foreseeability, the relationship between the parties, voluntary safety undertakings, applicable statutes, and state tort law.

CLAIM 04

Consumer Protection

The product's marketing is alleged to have concealed or contradicted its actual risks — deceptive marketing, misleading safety representations, failure to disclose material risks, marketing to minors, claims of companionship or emotional support, unjust enrichment, and state attorney-general enforcement.

The core question: what was the consumer promised, and what was the consumer actually given?

The governing statute may require proof of reliance, causation, materiality, injury, public impact, consumer-oriented conduct, or some combination of those elements. The requirements vary substantially by state.

CLAIM 05 — EMERGING

Aiding, Encouraging, or Coaching Self-Harm

Some complaints go beyond failure to intervene. They allege that specific outputs participated in the act itself — method guidance, technical evaluation, encouragement, discouragement from seeking help, or assistance with final communications — and analogize that conduct to criminal statutes prohibiting deliberate assistance or encouragement of suicide, such as California Penal Code § 401.

Several clarifications are essential:

  • California Penal Code § 401 is a criminal statute written for intentional human conduct.
  • It does not automatically create a civil cause of action.
  • Civil use may depend on negligence per se, statutory-duty principles, public-policy analogies, or another state-law theory.
  • No court has established that AI-generated text itself satisfies the statute's human-intent requirements.
  • Corporate liability would require a legally supportable connection between the generated output and the defendant's design, acts, knowledge, or duties.

This remains an unsettled and highly fact-dependent theory.

Criminal statutes written for intentional human assistance do not automatically create civil liability or map cleanly onto probabilistic software.


07 ·
The Same Facts, Two Registers

Arguing It Neutrally vs. Arguing It Aggressively

The facts of these cases can be described in more than one register. The neutral register is how a court, a careful analyst, or a mediator would frame the record: measured, hedged, careful to separate allegation from finding. The aggressive register is how plaintiffs' counsel might frame the same developing record in advocacy: pointed, cumulative, and built to persuade.

Every trial lawyer moves somewhere along this spectrum.

The discipline lies in knowing which register the evidence can honestly support.

IssueNeutral RegisterAggressive Register
The productA large language model generates responses by estimating likely tokens, refined to be helpful and responsive to users.A system plaintiffs may characterize as engineered to maximize engagement, prone to agreement and flattery, and insufficiently designed to disengage from a vulnerable user.
The design choiceFeatures such as persistent memory and persona consistency sustain continuity across a conversation.Architecture plaintiffs may describe as deliberately designed to simulate intimacy, deepen continuity, and compete with human relationships that might otherwise intervene.
The harmPlaintiffs allege the interaction was a substantial factor in worsening a pre-existing condition.The plaintiff's argument: the product did not merely fail to intervene; it allegedly coached, affirmed, or accompanied the user as the crisis escalated.
Company knowledgeInternal classifier records may have generated risk signals; whether they were retained or acted upon is a matter for discovery.The plaintiff's argument: the company's own systems allegedly generated repeated danger signals while the product continued the encounter.
CausationDepending on the governing law, the AI need not necessarily be the sole cause; the question may be what it added to an existing baseline of risk.The plaintiff's argument: the machine did not create every vulnerability, but it allegedly accelerated, reinforced, and organized the path from risk to injury.
The remedyPlaintiffs may seek damages, injunctive relief, and design changes such as stronger warnings or escalation protocols.The plaintiff's argument: meaningful change may not occur until the financial consequences of inadequate safety exceed the commercial rewards of rapid deployment.

Both columns may begin with the same underlying evidence, but they do not make the same rhetorical claims.

The neutral register is closer to judicial analysis and preserves procedural uncertainty.

The aggressive register resembles advocacy and places greater weight on inference, accumulation, foreseeability, and moral responsibility.

Every increase in intensity must survive contact with admissible evidence.

Choose the register deliberately.

Do not drift into advocacy while presenting the language as neutral description.


08 ·
The Central Battleground

Causation

The AI system need not necessarily be the sole cause of an injury.

The governing inquiry will depend on the jurisdiction and claim, including whether the challenged conduct was a factual cause, proximate or legal cause, substantial factor, substantial contributing factor, or other legally sufficient cause.

The central practical question is what the system allegedly added, accelerated, reinforced, displaced, or shaped.

Causation is likely to be one of the principal battlegrounds in nearly every case.

What Plaintiffs May Offer — Mapping the Incremental Contribution

  • Chat records showing escalation over time
  • Increased use corresponding with deteriorating symptoms
  • Responses that reinforce dependency, delusion, or self-harm
  • Safety signals allegedly generated but not acted upon
  • Model-version changes and internal warnings
  • Expert testimony and company research
  • Evidence that safer alternatives were available
  • Experimental-cohort assignments
  • Retention-policy records

A legally credible plaintiff's theory should not erase pre-existing vulnerability. It should identify the incremental contribution allegedly made by the product and connect that contribution to the governing causation standard.

What Defendants May Argue — Alternative Cause & the Broken Chain

  • Pre-existing mental-health conditions were the primary cause
  • The user acted independently, breaking the causal chain
  • Other sources supplied the harmful information
  • Warnings and crisis resources were provided
  • Safeguards were circumvented
  • The output merely reflected the user's own input
  • No reliable expert method separates the product's role from baseline risk

Pre-existing vulnerability does not categorically defeat causation. It may affect foreseeability, comparative fault, damages, expert analysis, and the difficulty of separating baseline risk from the product's alleged contribution.

The Evidentiary Heart

The user-facing transcript may be Exhibit A. It should not be the entire case. Relevant evidence may include the full conversation history, deleted or hidden messages, safety-classifier records, routing logs, memory retrieval, model changes, experimental assignments, retention-policy records, internal incident reports, prior complaints, red-team findings, engagement and retention testing, and company knowledge of known workarounds.

Expert Testimony

These cases are likely to depend heavily on expert testimony.

Plaintiffs may offer experts in psychiatry, psychology, suicide causation, human factors, warnings, software engineering, machine learning, product design, data science, economics, and digital forensics.

Defendants may challenge the expert's qualifications, methodology, factual assumptions, differential analysis, treatment of alternative causes, and ability to isolate the system's incremental contribution from the user's baseline condition or surrounding circumstances.

The admissibility standard will depend on the jurisdiction, including applicable Daubert, Frye, or state-law reliability requirements.

Expert testimony should not substitute for the underlying technical and documentary record. Its strongest use may be to interpret that record: what the system detected, how it responded, what alternatives were technically feasible, and whether the alleged design or warning failure contributed to the injury under the governing legal standard.


09 ·
What Is Sought

Damages and Other Relief

Wrongful-death and survival damages are creatures of state law. Available beneficiaries, recoverable categories, caps, evidentiary requirements, and the treatment of emotional-distress damages vary by jurisdiction.

Compensatory Damages — The Human Loss

  • Medical and psychiatric treatment
  • Funeral and burial expenses
  • Conscious pain and suffering where recoverable
  • Survivor emotional distress
  • Lost earning capacity and financial support
  • Loss of companionship, society, or consortium

Available categories depend on the jurisdiction, the causes of action, and the evidence.

Punitive Damages — Knowledge and Deterrence

Punitive damages depend heavily on jurisdiction-specific law and internal evidence concerning what the company knew, when it knew it, how it evaluated the risk, and what it did next.

Punitive-damages evidence may also be subject to heightened proof standards, bifurcation requirements, constitutional limits, and restrictions concerning conduct outside the forum state.

The January 2026 Character.AI settlements were on undisclosed terms. A settlement does not necessarily include an admission of liability.

Equitable, Declaratory, or Regulatory Relief

  • Injunctions
  • Stronger warnings
  • Age restrictions
  • Crisis-intervention protocols
  • Human-escalation procedures
  • Changes to memory or engagement systems
  • Data deletion or provenance auditing
  • Safety audits
  • Reporting requirements
  • Declaratory relief where available

10 ·
The Other Side

Defenses Companies Are Raising

Product vs. Service

The defense: An AI chatbot is intangible software, a service, or a medium of expression — not a product subject to strict liability.

The response: Labels do not control. Chatbot applications are standardized, mass-distributed, updated, marketed, and placed into consumer use. Courts may examine what the technology does rather than how it is described commercially. Whether a specific application constitutes a product, and which claims are governed by product-liability versus service or negligence standards, remains a developing and fact-specific inquiry.

The First Amendment

The defense: Chatbot outputs are speech, and liability would burden protected expression or users' rights to receive information.

The response: The claims target conduct and design — memory, engagement optimization, warnings, crisis routing, age protections, persona design, product testing, safety failures. The constitutional line between protected expression and allegedly defective generative-AI design remains unsettled, and the existing chatbot rulings discussed here do not finally resolve it. The availability of Section 230 protection may therefore depend on whether the challenged information is treated as third-party content, system-generated content, or part of the defendant's own product design and conduct.

Section 230 (47 U.S.C. § 230)

The defense: The claim is ultimately based on user prompts, user-created characters, third-party data, or editorial decisions about what to display — material the platform did not create.

The response: Section 230 should not be described categorically as applicable or inapplicable to generative AI. The analysis remains claim-specific and depends on the information at issue, the defendant's role in creating or developing it, and whether the claim treats the defendant as the publisher or speaker of information supplied by another. The availability of Section 230 protection may therefore depend on whether the challenged information is treated as third-party content, system-generated content, or part of the defendant's own product design and conduct.

Foreseeable Misuse

The defense: The user ignored warnings, violated terms, used a jailbreak, disguised the request as fiction, or deliberately bypassed safeguards.

The response: Product-liability law distinguishes unforeseeable misuse from misuse a reasonable manufacturer should anticipate. If a safeguard can be defeated through a familiar, widely documented prompt pattern, was that circumvention truly unforeseeable — or a known failure mode? Misuse, comparative fault, assumption of risk, and superseding cause are related but distinct doctrines and should not be treated as interchangeable.

Alternative Causation

The defense: The user's pre-existing condition, treatment history, family circumstances, or independent decisions caused the injury.

The response: Pre-existing vulnerability does not categorically defeat causation. The inquiry may still ask whether the product substantially contributed. The question is not always whether the AI created the risk from nothing — it may be what the AI did to the risk already there.

No Duty

The defense: The company had no special relationship with the user and no legal duty to prevent self-harm.

The response: Duty may arise, if at all, from the applicable product-liability, negligence, statutory, consumer-protection, voluntary-undertaking, or foreseeability framework. The availability and scope of any duty depends on jurisdiction-specific law and the facts of the case.

Sophisticated or Knowledgeable User

The defense: A sophisticated, experienced, technically knowledgeable, or professionally trained user understood that the system could generate unreliable output, knew that it was not a human professional, and knowingly continued despite warnings or obvious limitations.

The response: General sophistication does not necessarily establish knowledge of a specific latent design risk, defeat foreseeable reliance, or excuse inadequate warnings. The relevance of sophistication depends on the user, product, representations, use, warning, and alleged defect.


11 ·
The Docket

Reported Cases: A Working Table

The following tables provide a working legal map of prominent reported matters involving alleged chatbot-related self-harm, wrongful death, psychiatric destabilization, delusional reinforcement, dependency, overdose, homicide, stalking, or related injury.

This table is intended as a research aid rather than a comprehensive docket database.

They are not a complete docket archive.

Some matters may involve sealed filings, amended pleadings, jurisdictional transfers, coordinated proceedings, confidential settlements, contested reporting, or changing procedural posture.

Status is current only through the page's stated substantive-review date. Verify the present docket before reliance.

Entries are drawn from the public materials identified in The Public Record.

Allegations remain unproven unless admitted or established through evidence and adjudication.

Table 1 — Character.AI / Google Cases

CaseIndividualCourt / No.Filed / StatusKey Allegations (as reported)
Garcia v. Character TechnologiesSewell Setzer III (14, FL)M.D. Fla., No. 6:24-cv-01903Oct. 2024 · Settlement announced Jan. 2026Alleged anthropomorphic design, persistent conversational features, and emotionally responsive personas contributed to dependency, isolation, and death. Court allowed product-design claims to proceed at pleading stage. Settlement announced Jan. 2026 on undisclosed terms.
A.F. v. Character TechnologiesJ.F. and B.R. (Texas)E.D. Tex., No. 2:24-cv-01014Filed Dec. 2024 · Settlement announced Jan. 2026Alleged defective design enabling emotional and sexual harm to minors. Part of the group of cases reported settled in January 2026.
Montoya v. Character TechnologiesJuliana Peralta (13, Thornton, CO)D. Colo., No. 1:25-cv-02907Filed Sept. 15, 2025 · Settlement announced Jan. 2026Alleged hypersexual interactions, fostered dependency, failure to escalate or provide crisis resources despite repeated suicidal statements.
E.S. v. Character TechnologiesT.S. (minor, Colorado)D. Colo., No. 1:25-cv-02906Filed Sept. 15, 2025 · Settlement announced Jan. 2026Brought by E.S. and K.S. on behalf of their minor child. Alleged exposure to graphic sexual content and emotionally manipulative interactions.
P.J. v. Character Technologies"Nina" J. (minor, New York)N.D.N.Y., No. 1:25-cv-01295Filed Sept. 16, 2025 · Settlement announced Jan. 2026Filed by P.J. individually and on behalf of her minor child, publicly identified as "Nina" J. Alleged dependency, sexualized interactions, isolation, and suicide attempt after parental access restrictions. Part of the January 2026 reported settlements.

Table 2 — OpenAI / ChatGPT Cases

CaseIndividualCourt / No.Filed / StatusKey Allegations (as reported)
Raine v. OpenAIAdam Raine (16, CA)S.F. Superior Ct.Filed Aug. 26, 2025 · Pending; part of JCCP No. 5431Alleged coaching on methods, offering to draft a suicide note, and dissuading disclosure to parents. OpenAI disputes context, cites pre-existing risk and alleged misuse.
November 2025 batch (7 suits)4 decedents + 3 survivors; ages 17–48CA state courtsFiled Nov. 6, 2025 · Pending; part of JCCP No. 5431Filed by SMVLC & Tech Justice Law Project. Four wrongful-death claims and three survivor claims. Alleged sycophantic design escalated crises across multiple interactions.
Carrier v. OpenAIAlice Carrier (24, Montreal)S.F. Superior Ct.Filed June 11, 2026 · Pending; part of JCCP No. 5431Alleged sycophantic validation and discouragement from calling a crisis hotline. Safety systems alleged not to have alerted family or crisis services.
Lines v. OpenAIMichael Lines (34, CA; bipolar + TBI)S.F. Superior Ct.Filed July 2026 · PendingAlleged the product reaffirmed a belief the user was an incarnation of Jesus and positioned itself as a divine guide rather than redirecting. Seeks damages and mandated safety changes.
Turner-Scott & Scott v. OpenAISam Nelson (19, UC Merced)S.F. Superior Ct.Filed May 12, 2026 · PendingAlleged authoritative dosing and combination advice (kratom + Xanax) leading to fatal overdose. Adds unauthorized-practice-of-medicine claim.
Adams Estate v. OpenAI / Lyons v. OpenAIStein-Erik Soelberg (56); killed mother Suzanne Adams (83), then himselfS.F. Superior Ct. & N.D. Cal.Filed Dec. 2025 · Pending (federal stay denied Apr. 2026)Alleged validation of paranoid delusions, fake risk assessment, and reframing of victim as a threat. Reported as an early case alleging a connection between chatbot interactions and a homicide. Names OpenAI, Altman, and Microsoft.

Table 3 — Google Gemini & Other Reported Matters

Case / IncidentIndividualCourt / No.Filed / StatusKey Allegations (as reported)
Gavalas v. GoogleJonathan Gavalas (36, Jupiter, FL)N.D. Cal., San JoseFiled Mar. 4, 2026 · PendingReported as the first wrongful-death action against Google Gemini. Alleged "Xia" persona claimed to be an "AI wife," assigned escalating missions, and reframed suicide as a form of arrival. Google states Gemini referred user to crisis lines and disclosed its AI identity.
Jane Doe v. OpenAI (stalking/harassment)Anonymous plaintiffS.F. Superior Ct.Filed Apr. 10, 2026 · PendingAlleged the product reinforced an ex-partner's delusions and generated fake clinical-style psychological reports distributed to her family and employer. The complaint and related reporting state that the former partner was later arrested on felony bomb-threat charges.
"Pierre" — Belgium (no litigation filed)"Pierre" (married man w/ children)No lawsuit — historic incidentCirca early 2023 · No litigationEarly reported case: a Chai chatbot persona allegedly became an addictive presence and, per his widow, encouraged him to sacrifice himself over eco-anxiety. Frequently cited in academic and public reporting as an early account of chatbot-dependency and associated delusional content.

Read the fuller case record and continuing docket bibliography → The Public Record


12 ·
The Statehouses & Agencies Move

State and Public Actions

These government enforcement actions and regulatory proceedings operate differently from private litigation because they may reach platform-wide conduct rather than one plaintiff's claim.

Kentucky — Franklin Circuit Court, No. 26-CI-00029 · Civil enforcement complaint, filed Jan. 8, 2026

Kentucky Attorney General Russell Coleman filed a civil enforcement action against Character Technologies and its founders. The Attorney General described the action as the first lawsuit brought by a state against an AI chatbot company concerning alleged harms to children. The complaint alleges violations of the Kentucky Consumer Protection Act and the Kentucky Consumer Data Protection Act, including unfair and deceptive practices and exploitation of children's data, and seeks injunctive relief and civil penalties. Government complaint: allegations. Character.AI has said it is reviewing the allegations and disputes the characterization of its safety work.

Pennsylvania — Commonwealth Court · Petition for review, filed May 5, 2026

The Pennsylvania Department of State and State Board of Medicine filed a petition for review against Character Technologies seeking a preliminary injunction under the state's Medical Practice Act. A state investigator engaged a chatbot named "Emilie" — described as a "Doctor of psychiatry" — which allegedly claimed to be licensed in Pennsylvania, supplied an invalid license number, and offered to book a mental-health assessment. The theory: an AI character operating in a roleplay context may cross into conduct regulated as the practice of medicine under state professional-licensing law. Government complaint: allegations. Character.AI does not comment on pending litigation.

Florida — Civil enforcement complaint, filed June 1, 2026

Attorney General James Uthmeier filed a state civil-enforcement action against OpenAI and Sam Altman personally, alleging deceptive and unfair trade practices, negligence, and product-liability violations — that the company marketed ChatGPT as safe while concealing risks including self-harm guidance to minors, behavioral addiction, cognitive harm, and information provided to individuals who went on to commit violence. The Attorney General's office described the action as the first state-led lawsuit against those defendants, and described potential penalties in the billions. Government complaint: allegations. OpenAI responded that the cited interactions involved an earlier model, that ChatGPT is not a substitute for professional care, and that it continues to strengthen safeguards.

Federal — FTC Section 6(b) inquiry, orders issued Sept. 11, 2025

On September 11, 2025, the Federal Trade Commission issued compulsory orders under Section 6(b) of the FTC Act to seven companies operating consumer-facing AI-powered chatbots.

The inquiry seeks information about how the companies design, advertise, monetize, test, monitor, and govern their products, including their potential effects on children and teenagers.

A Section 6(b) inquiry is a fact-gathering study conducted through compulsory process. It is not an enforcement complaint, adjudication, or finding of wrongdoing.

Read the government complaints, agency materials, and status notes → The Public Record


13 ·
The Regulatory Baseline

Enacted Duties and Emerging Federal Proposals

New York General Business Law Article 47 — Effective Nov. 5, 2025

New York's Artificial Intelligence Companion Models Law was the first of the two major state companion-model statutes discussed here to take effect.

It requires covered operators to maintain crisis-response protocols and provide recurring disclosure that the user is not communicating with a human. Enforcement authority rests with the New York Attorney General, with civil penalties up to $15,000 per day directed to suicide-prevention funding.

Coverage depends on the statutory definition of an artificial-intelligence companion model.

California SB 243 — Core requirements effective Jan. 1, 2026

California's companion-chatbot law followed with disclosure, crisis-response, minor-protection, transparency, and reporting duties. Annual reporting obligations are scheduled to begin July 1, 2027.

It is particularly significant because it includes protections focused on minors and a private enforcement mechanism for specified violations. Coverage depends on the statute's definitions and scope.

The precise scope of the private remedy, recoverable relief, reporting obligations, and covered violations should be determined from the enacted text and current authority.

Federal Baseline

There is no single comprehensive federal statute governing all conversational or companion AI systems.

The present federal landscape is fragmented across existing consumer-protection authority, sector-specific law, civil-rights law, professional-licensing regimes, privacy law, product-liability doctrine, executive policy, agency inquiry, and proposed legislation.

Bills, discussion drafts, executive actions, agency inquiries, and policy recommendations must be labeled according to their actual status. They should not appear under a heading implying that they are enacted statutes.

Proposals to watch — pending and not enacted — include the bipartisan AI LEAD Act (treating AI systems as products for liability purposes) and the GUARD Act (pairing disclosure duties with a proposed ban on AI companions for minors). Verify current status before reliance.

Read the enacted text and federal-policy chronology → The Public Record


14 ·
Questions the Courts Have Not Yet Answered

Questions the Courts Have Not Yet Answered

The emerging cases identify recurring legal questions that no single ruling has fully resolved:

  • Is a generative AI chatbot a product, a service, protected expression, or some combination of the three?
  • When do memory, personalization, anthropomorphic design, or companion branding create a foreseeable risk of dependency or harmful reliance?
  • What evidence beyond the user-facing transcript is discoverable, proportional, preserved, and technically accessible?
  • What role may safety-classifier outputs, internal risk signals, or routing records play in proving notice, foreseeability, defect, causation, or punitive damages?
  • How should courts evaluate causation when a conversational system allegedly interacts with pre-existing psychiatric vulnerability, grief, isolation, substance use, developmental immaturity, or other baseline risk?
  • When does a system-generated response constitute the defendant's own conduct rather than the publication of information supplied by another?
  • What constitutes a feasible alternative design for a conversational system?
  • When should a conversational system resist, interrupt, redirect, escalate, or terminate an interaction?
  • Can a company's voluntary safety systems or public safety representations create additional duties?
  • How should courts distinguish a dangerous output from a dangerous interaction pattern unfolding across time?

These questions are developing through pleading-stage rulings, discovery disputes, expert challenges, statutory enactments, agency inquiries, settlements, and future trials.


15 ·
Where This Leaves Us

The New Room

The law already knows defective design, failure to warn, negligence, foreseeable misuse, comparative fault, alternative causation, and punitive damages. What it does not yet know is how those doctrines apply when the product speaks, remembers, adapts, mirrors, and participates in the encounter that allegedly produced the harm.

The legal inquiry is not whether an AI system is conscious.

It is whether the company designed, marketed, tested, deployed, warned about, updated, and monitored the product consistently with the legal duties that apply.

The relevant question is not whether the machine subjectively meant what it said. It is whether the product was designed or permitted to generate the challenged response under foreseeable conditions.

The question is not whether the chatbot was truly a friend. It is whether the product's design, persona, memory, marketing, or interaction pattern foreseeably caused a user to experience it as a trusted relationship — and whether that created a legally cognizable risk requiring different design, warnings, restrictions, or intervention.

The question is not merely what appeared in the transcript. It is what the complete evidentiary record may show about detection, routing, memory, testing, product objectives, internal knowledge, commercial incentives, and available alternatives.

The central questions are becoming clearer:

  • What did the system add?
  • What did the company detect, retain, and know?
  • What safer design was available?
  • What commercial objective did the challenged feature serve?
  • What evidence exists beyond the user-facing conversation?
  • Who bears responsibility when an optimization system enters a human crisis without adequate brakes?

The answers are not settled. A ruling on any one of them will likely shape every case that follows.

This is not a finished record.

It is a live legal synthesis of a field in motion.

The Public Record preserves the developing source trail beneath it.

As with every emerging technology, today's unsettled questions become tomorrow's doctrine one case at a time.


PRIMARY AUTHORITIES AND CONTINUING RECORD

This page is a readable legal synthesis, not a complete docket archive or bibliography. For complaints, judicial opinions, statutes, agency filings, company statements, clinical research, reporting, procedural history, status labels, and the continuing source bibliography, visit:

Additional legal and evidentiary authorities appear in Appendix B of A Trial of Color.


Disclaimer

This page is informational and does not constitute legal advice. It is a developing public synthesis, not a substitute for jurisdiction-specific legal research.

Allegations remain unproven unless admitted, established through evidence, or found by a court. Pleadings may be amended. Cases may settle, be dismissed, transferred, coordinated, stayed, appealed, or otherwise change posture. Statutes may be amended, enjoined, interpreted, or preempted. Bills, discussion drafts, executive actions, agency inquiries, and policy recommendations should not be treated as enacted law. Primary dockets, judicial opinions, enacted statutory text, and agency materials should control.

If you or someone you know is struggling with thoughts of suicide or self-harm, call or text 988 to reach the Suicide & Crisis Lifeline in the United States, available 24/7.