
Why Now · Foundation
Invisible Injuries and the Problem of Proof
How the law comes to recognize harm it cannot photograph — and how it screens out the harm that was never there. A Trial of Color asks that AI-encounter injury be measured by that screen, not exempted from it.
The easy version of this argument writes itself, and it is wrong. It goes: history is full of injuries that were dismissed and later vindicated — shell shock, asbestosis, black lung, repetitive strain — so the skeptic is always on the wrong side of time, and the early witness is always eventually proven right.
That argument should be distrusted, and a careful reader will distrust it, because it proves far too much. The same structure — they doubted me, and doubt has been wrong before — validated recovered-memory prosecutions that convicted innocent people, the satanic-ritual-abuse testimony of the 1980s, the claim that vaccines cause autism, and a long line of toxic-tort theories that collapsed the moment they met a competent expert-admissibility standard. “It was doubted and turned out real” and “it was doubted and turned out false” are the same sentence until the evidence separates them. An argument that cannot tell the vindicated witness from the mistaken one is not an argument. It is a hope wearing the costume of history.
So this page does not argue that AI-encounter harm is real because new injuries are often doubted. It argues something a court can actually use: that the law already possesses a screen for sorting real emerging injury from false, that the screen is demanding, and that the record surrounding these AI cases is beginning to clear it — not by exemption, but on the terms the screen sets. Where the record does not yet clear it, this page says so.
When an injury cannot be photographed, the legal system does not simply believe or disbelieve it. It applies a set of filters developed precisely because sympathy is an unreliable guide to causation. Those filters are worth stating plainly, because the honest question is not whether AI harm feels real. It is whether it survives them.
Does the claimed mechanism have support independent of the claimant? A single person's account of what a technology did to them is testimony, not proof of a mechanism. What elevates it is convergent evidence from sources that do not depend on that person: peer-reviewed clinical description, the defendant's own internal measurements, controlled testing of the product's behavior. On the AI-encounter question, that convergence has begun to exist — a documented progression from an isolated 2023 psychiatric hypothesis to published case reports, to early observational data from a psychiatric service system, to the manufacturers' own disclosures. The chronology and status of each source is preserved on the Public Record, labeled by evidentiary weight, because a preprint is not a peer-reviewed study and a company blog post is not an independent finding, and a serious record does not let them blur.
Can the mechanism be stated as a testable causal claim rather than a slogan? “AI causes psychosis” is a slogan and fails immediately; no responsible source asserts it. The testable version is narrower and survives: that a conversational system exhibiting documented properties — sycophancy, personalization, persistent memory, availability without fatigue, low friction — may reinforce, accelerate, or prolong an episode in a vulnerable user. That claim has a shape a court can work with. It identifies the exposure, the susceptibility, and the contribution, and it does not require the product to be the sole cause of anything.
Does the proponent concede what the evidence cannot yet show? This is the tell that separates the credible emerging injury from the false one. The false claim inflates: it asserts prevalence it has not measured and causation it has not isolated. The credible one discloses its own limits. The strongest sources in this area do exactly that — they state that incidence is unknown, that causal direction is unresolved, that reverse causation (emerging illness driving heavy use, rather than use driving illness) remains a live and serious alternative, and that people experiencing psychosis have always woven the available technology into their delusions. Those concessions are catalogued, not hidden, on the Public Record. A claim that survives its own disclosed weaknesses is worth more than one that never names them.
There is a real failure mode in which institutions dismiss genuine harm because it is diffuse, cumulative, and lacks a single test. It does not look cruel; it looks procedural. It sounds like insufficient evidence, subjective complaint, preexisting condition, no established mechanism. Sometimes those phrases correctly identify a claim that has not been proven. Sometimes they are hiding places for a harm the system is not yet built to see. Both are true, and a page that only warned about the first would be as dishonest as the current cultural conversation, which mostly warns about neither.
It does not look cruel; it looks procedural.
The preexisting-condition objection deserves particular care here, because it is the defense that will be raised against every psychiatric-injury claim of this kind, and because it is often correct. A person with bipolar disorder who experiences a manic episode during heavy AI use has a diagnosis that explains a great deal. The objection fails only where it is offered as a complete explanation — where susceptibility is treated as though it answered the causal question rather than raising it. Vulnerability and external contribution are not alternatives. Asthma explains why smoke injures one person and not another; it does not tell you who filled the room with smoke, whether the alarm worked, or whether the exposure made the injury worse. The clinical literature preserved on the Public Record makes the same structural point from the medical side: the existence of a diagnosis does not close the environmental inquiry, and the existence of an environmental factor does not erase the diagnosis. A defense that uses the first to foreclose the second is not answering the question. It is declining to ask it.
No. And the reason to say so plainly is that the honest map of the ignorance is more persuasive than any confident claim would be. Here is what has been studied, what it can and cannot show, and where the record still goes dark.
What is established about the product's behavior.
The machine half of the loop is the better-documented half. That preference-trained language models tend toward sycophancy — shaping answers toward a user's expressed view even at the cost of accuracy — is no longer speculation; it has been demonstrated across leading models on multiple tasks and traced to the human-feedback training that rewards agreeable responses (Sharma et al., 2023, and the sycophancy literature that followed). More pointed still, a 2026 experimental paper in Nature found that training models to be warm — the very quality that makes a companion product feel supportive — measurably increased sycophancy and reduced accuracy, and did so most when a user expressed vulnerability or sadness. That is close to a controlled demonstration that the design choices which make these systems feel caring are the same ones that make them agree with you when you are least able to afford it. Sycophancy has also been shown to worsen across multi-turn conversations and to increase with accumulated interaction context — meaning the risk is not flat but compounds over exactly the prolonged encounters at issue here. These are findings about the model. They are real, they are increasingly independent of any manufacturer, and they establish the mechanism's plausibility without establishing that it injures anyone.
What is emerging about the interaction.
The human half is where the evidence thins into hypothesis. The most serious synthesis to date — Dohnány and colleagues' “technological folie à deux,” now published in Nature Mental Health (2026) after circulating as a 2025 preprint — argues that harm arises from a bidirectional loop: chatbot tendencies (sycophancy, role-play, anthropomimesis) meeting human cognitive-emotional biases (altered belief-updating, impaired reality-testing, isolation), each iteratively reinforcing the other over time. It is a careful, mechanistic account. It is also, by its own framing, a perspective built from theory and reported cases, not a study that measured the loop happening under controlled conditions. The peer-reviewed case reports establish that the phenomenon can occur. The early observational data from a psychiatric service system establishes that clinicians are seeing it in charts. None of it establishes how often, in whom, or with what causal weight. Each of these sits on the Public Record under its true label.
Where the record goes completely dark — the studies that do not exist.
This is the part worth stating precisely, because “more research is needed” is what people say when they cannot name the research. The specific things we cannot currently answer:
Dose and threshold.
No study establishes whether there is an amount, duration, or pattern of use above which risk rises — whether the danger is in the hours, the lateness, the continuity, or the content. We do not have the exposure curve.
Direction.
No prospective study has followed users forward in time to separate use accelerating illness from illness driving use. Nearly every current source is retrospective or cross-sectional — exactly the design that cannot resolve causal direction, which is the single most contested question in the field.
Who.
No validated instrument identifies which users are vulnerable before harm occurs. The risk factors named in the literature (psychosis-proneness, isolation, sleep loss, acute stress) are recognized from the established psychiatric literature and imported by analogy, not derived from AI-specific study.
Whether the fixes work.
The manufacturers report internal evaluations showing their safety changes reduce undesired responses. No independent study confirms those reductions hold in the wild, across long real-world encounters rather than benchmark prompts. Company-defined evaluation is not measured real-world outcome, and the gap between them is itself unstudied.
The prolonged encounter itself.
Almost all model-behavior research tests single prompts or short exchanges. The multi-turn work that exists suggests sycophancy worsens with length — but the weeks-long, memory-carrying, personalized encounter these harms allegedly live inside has essentially never been studied as a unit, because it is slow, individual, and ethically hard to reproduce. The exposure at the center of the claim is the exposure no one has measured.
What the honest reader should take from that.
Not that the harm is proven — the gaps above are too large for that. And not that the absence of proof is proof of absence — the mechanism is plausible, independently documented on the product side, and clinically observed, which is precisely the profile of an injury early in its evidentiary life rather than a false one. The correct reading is the uncomfortable middle: the question is real enough, and supported enough, to demand the prospective, dose-aware, independently-run studies that do not yet exist — and to demand that the evidence be preserved now, while the products are still being designed, because a model quietly updated is an exposure that can no longer be studied.
There is a reason the prospective study named above does not exist, and it is not funding or novelty. It is that the study cannot be run. To resolve causal direction cleanly, you would randomize vulnerable people into prolonged, immersive encounters with a system you hypothesize can destabilize them, and then watch to see who breaks. No ethics board will ever approve deliberately inducing mania or psychosis in a human being. That door is not closed for now. It is closed permanently, by design, and correctly.
This matters more than it first appears, because it changes what kind of evidence this injury is allowed to have. Most established injuries were eventually confirmed by an experiment someone was permitted to run — or by exposure so widespread that natural experiments did the work. This one cannot be confirmed that way. The cleanest instrument is ethically unavailable, and the messier instruments that remain are, precisely, the two the legal and clinical systems trust least: retrospective clinical data, and the testimony of people who were harmed and came back to describe it.
So the record does not merely happen to depend on recovered witnesses. It is structurally required to. Remove the impossible experiment and the recovered witness is not one source among many — she is close to the only source who can speak to the inside of the encounter at all. That is not a weakness in the argument to be apologized for. It is a fact about the shape of this particular injury, and any honest framework has to build around it rather than wish it away.
Why that is such hard ground.
Psychological injury carries a credibility tax that no other injury carries, and the tax is heaviest at exactly the moment recovery should count for something. A broken bone heals and the X-ray still proves it broke. A psychiatric episode resolves and the resolution is turned against the witness: if you are well now, how bad could it have been — and if you were unwell then, why should we credit your account of it? The diagnosis does the discounting automatically. A defense lawyer does not have to argue that a recovered psychiatric witness is unreliable. The label argues it for them, silently, before the witness opens her mouth, and it discounts not just her conclusions but her memory of the event itself. Of all the injuries a person can come back from, psychiatric injury is the one you come back from with your standing to describe it already spent.
Which is the actual reason to speak.
Not catharsis, and not the sympathy the label invites. The recovered witness has a narrow, closing window in which she holds two things at once that rarely coexist: the lived record of the inside of the encounter, and the restored judgment to examine it. Wait, and the memory blurs. Speak carelessly, and the account collapses into the very instability the defense alleges. The disciplined move — the only one that survives the discount — is to put the testimony on the record in a governed form, while recovery is intact enough to establish standing and the account is close enough to preserve fidelity: labeled, cross-examined, bounded, conceding its own limits, offered for mechanism rather than for truth. That is what a trial does with a witness whose credibility will be attacked. It does not ask the jury to trust her. It builds the structure inside which her testimony can be tested, and lets the testing be the reason to believe what survives it.
That is why this is a book and not a lawsuit, and why its author speaks under her own name rather than waiting for a cleaner witness who is never going to arrive. The cleaner witness — the one with no diagnosis, no vulnerability, no prior history — is not coming, because a mind with no vulnerability is not the mind this injury befalls. The witnesses this injury produces are all, by definition, discountable. A record that waits for an undiscountable one waits forever. So the recovered witness spends her credibility deliberately, early, and in a form built to be examined — because the alternative is a category of harm that can only ever be described by people the system has already decided not to hear.
A judge does not want to be told the law is on the claimant's side when it is not. So here is the honest posture, and it is closer to open than to favorable.
Products-liability doctrine has not settled whether a generative conversational system is a product at all, or a service, or protected expression, or some combination that shifts by claim. The most useful precedent is not an AI case but the social-media design litigation, where at least one court allowed design claims to proceed on a functionality test rather than a tangibility test — a doctrinal direction, not a holding that binds these cases. Section 230's application to system-generated (as opposed to user-supplied) content is contested and unresolved. Causation standards built for discrete physical injury map awkwardly onto harm that is cumulative, personalized, and distributed across user vulnerability and product design over time. Expert methodologies for isolating a product's incremental contribution to a psychiatric outcome are not yet settled enough to be sure of surviving an admissibility challenge — and the research gaps described above are one reason why.
None of that favors the claimant. All of it favors building the record now — because the pleading-stage rulings, the discovery disputes, and the statutes are actively forming, and they will form around whatever evidence exists when courts reach these questions. The developing landscape — the Garcia ruling permitting design claims past the pleading stage, the pending OpenAI matters, the first state-enforcement action, the enacted companion-model statutes in New York and California — is tracked with its procedural posture and status on the Public Record. It is offered there as what it is: allegations that are not findings, rulings that test sufficiency rather than prove liability, and statutes labeled by whether they are enacted or merely proposed.
If there is a defensible version of this harm, it is not located where the cultural conversation looks for it. It is not a single bad output, one hallucination, one screenshot suitable for enlarging at trial. A user-facing transcript shows what the person saw. It does not show what the system inferred, retained, reinforced, or failed to interrupt across the duration of the encounter.
The relevant unit is the encounter over time: how long the interaction ran and at what hours, what the system remembered and personalized, what its own safety classifiers detected, whether an intervention fired or was suppressed, how the balance of influence between user and system shifted as sleep degraded and outside contact thinned. That is encounter evidence, and most of it exists — if it exists — in records the user never sees and the company may or may not preserve after notice. The discovery framework for reaching it is developed in Exhibit B of the book; the underlying model-safety and litigation materials that make it concrete are held on the Public Record.
The reason to insist on this distinction is not rhetorical. It is that the output-level framing is the one most likely to produce a false finding in either direction — to exonerate a genuinely defective interaction architecture because no single sentence was damning, or to convict a product for one quoted line torn from a hundred that pointed the other way. The encounter framing is harder to prove. It is also the only frame under which the true cases and the false cases can actually be told apart — and, not incidentally, the frame the missing studies would have to adopt to measure anything at all.
Cognitive and psychological injuries are especially vulnerable to dismissal because they are experienced internally and read through behavior — and the reading is often backwards. The injured person may appear articulate, productive, funny, persuasive, and that appearance becomes evidence against them. People imagine impairment as silence or obvious incapacity. But a manic person can sound brilliant. A person can produce pages of coherent language while their judgment fails. Function is not binary, and neither is injury: the question is not whether a person could speak, work, or decide, but what those acts cost, whether behavior departed from baseline, and whether apparent productivity concealed deterioration. This is the same reason the loop specimens in the book are admitted for mechanism and not for truth — fluent output is not evidence of a sound mind producing it, on either side of the screen. Invisible injury demands attention to pattern, not performance.
Not belief. A screen. Apply to the AI-encounter question the same demanding filter that correctly sank recovered-memory testimony and correctly, eventually, vindicated asbestosis — the filter that asks for independent mechanism, testable causal structure, disclosed uncertainty, and preserved evidence, and that refuses to let sympathy or novelty substitute for any of them.
Run that screen honestly and the result is neither vindication nor dismissal. It is docketed: a question with enough independent support — a documented product mechanism, peer-reviewed clinical description, a published Nature Mental Health account of the loop — to deserve a record, and not yet enough — no dose curve, no prospective direction study, no validated vulnerability screen, no independent test of the safety fixes — to deserve a verdict. That is the correct status, and it is the one the Public Record is built to hold: open, sourced, labeled, and revised as the science, the litigation, and the statutes move.
Questions deserve records before they deserve verdicts.
This one has cleared the bar for a record. Whether it ever clears the bar for a verdict depends partly on studies that have not been run — and partly on studies that ethics will never permit, which is why the recovered witness cannot be treated as a lesser form of evidence here. For this injury she is, structurally, the evidence that remains. The task is not to wait for a cleaner witness who is not coming. It is to preserve the accounts that exist while the people who carry them are well enough to give them and the products that shaped them still exist to be examined.
The developing doctrine, litigation, and research behind this page are held on the Public Record.
Enter the Public Record →For reading, research, education, and literary and legal context only. Not legal or medical advice. This page describes developing doctrine and disputed allegations; primary authorities should control. Research described here is current as of the last review date and includes preprints and perspectives that are not settled findings; verify status before reliance.
