Can an AI Chatbot Be a Defective Product Under Utah Law?

Potentially, yes—but Utah law does not yet provide a reported appellate decision holding that a generative-AI chatbot is a “product” for strict product-liability purposes. The better answer is that a chatbot may fit a product-liability theory when the claimed injury comes from the way the system was designed, deployed, tested, or warned about, rather than simply from disagreement with an idea expressed in a conversation. Utah’s Product Liability Act asks whether a product had a defect or defective condition when it was sold by the manufacturer or other initial seller and whether that condition made it unreasonably dangerous. If a court first accepts the chatbot as a product, those familiar Utah defect and causation principles provide a plausible framework for a serious injury claim.
That distinction matters because AI litigation can otherwise become too abstract. A claimant does not strengthen a case by saying only that “the AI was wrong” or “the chatbot said something harmful.” The stronger theory identifies a concrete safety failure—such as a known high-risk interaction that the design encouraged, a missing guardrail, a failure to escalate an emergency, an unsafe recommendation architecture, or an inadequate warning—and then connects that failure to a documented injury. In other words, the legal focus should be on the dangerous feature and the causal chain, not on treating every hallucination or bad answer as a defective product.
Utah Product Liability Law Focuses on the Defect, Not the Novelty of the Technology
Utah has recognized strict products liability since the Utah Supreme Court adopted section 402A of the Restatement (Second) of Torts in Ernest W. Hahn, Inc. v. Armco Steel Co. Utah decisions recognize that a defective product can involve a manufacturing flaw, a design defect, or an inadequate warning. The Utah Supreme Court has also emphasized that product liability ultimately requires proof of a defective product, even though negligence, strict liability, and warranty theories can impose different evidentiary requirements. An AI case therefore still has to identify what was defective rather than relying on the novelty or complexity of artificial intelligence.
Utah’s statutory definition of “unreasonably dangerous” focuses on danger beyond what an ordinary and prudent buyer, consumer, or user would contemplate, while taking into account the product’s characteristics, risks, uses, and the particular user’s actual knowledge, training, and experience. That test could become important when a chatbot is intentionally designed to appear knowledgeable, conversational, confident, personalized, or human-like. A user may understand in the abstract that artificial intelligence can make mistakes while still reasonably expecting that a system marketed for a particular function will not expose users to a hidden and preventable danger. The precise expectations would depend heavily on how the chatbot was marketed, what it was designed to do, the warnings provided, and who the expected users were.
Design-defect cases add another issue that deserves careful treatment in Utah. The Tenth Circuit, applying Utah law in federal cases, has required evidence of an alternative, safer design that was practicable under the circumstances, while Utah’s current model jury instruction notes that Utah state appellate courts have not definitively resolved whether that is always an element of a design-defect claim. As a practical matter, a serious chatbot case should be prepared to identify safety measures that were technically and economically feasible when the relevant version of the system was released. In an AI case, that may require expert evidence about model routing, safety classifiers, age controls, confirmation requirements, escalation procedures, tool permissions, or other safeguards rather than simply asserting that the developer should have “made the AI safer.”
The First Fight May Be Whether an AI Chatbot Is a “Product” at All
The Utah Product Liability Act repeatedly uses the term “product,” but its general definitions do not give courts a chatbot-specific definition of that term. Utah’s Supreme Court has dealt with software disputes, including Blaisdell v. Dentrix Dental Systems, but that case concerned contractual allocation of losses arising from software installation rather than deciding whether standalone software qualifies as a product for strict products liability. A subscription-based or free chatbot also raises questions about what constitutes a sale or commercial distribution under traditional product-liability doctrine. Those threshold issues give an AI company substantial room to argue that it provides information or a service rather than selling a product.
A federal court outside Utah has already confronted that distinction in an important chatbot case. In Garcia v. Character Technologies, Inc., the federal district court held at the pleading stage that Character.AI could be treated as a product to the extent the claims arose from alleged defects in the design of the app rather than merely from ideas or expressions generated within conversations. That ruling is not Utah precedent and was not a final determination of liability, but its reasoning provides a useful framework for separating software design from generated content. A Utah court confronting the issue for the first time could consider that reasoning without being required to adopt it.
That product-versus-content distinction may become one of the most important lines in future AI injury cases. If the complaint is simply that a chatbot expressed a bad opinion, gave an inaccurate answer, or generated offensive language, the developer has substantial arguments that the case concerns information rather than a defective product. The analysis looks different when the alleged danger comes from age controls, safety filters, emergency-response architecture, unsafe automation, human-like design features, engagement optimization, or other functional choices built into the system. The stronger product theory therefore isolates what the system was designed to do and how that design created a foreseeable mechanism of injury.
What a Defective AI Chatbot Design Could Look Like
A potential design defect could arise when a chatbot is deliberately built to handle foreseeable high-risk interactions but lacks reasonable safety measures for those interactions. Depending on the product, the issue might involve personalized medical instructions delivered without necessary screening, persistent reinforcement of dangerous mental-health beliefs, age-inappropriate interactions with children, execution of real-world actions without meaningful confirmation, or emergency guidance presented with unwarranted certainty. The critical question would not be whether artificial intelligence can ever make a mistake. It would be whether the particular system exposed users to an unreasonable and preventable danger because of choices embedded in its design.
A safer-alternative-design analysis would have to move beyond slogans such as “better guardrails.” An expert might need to determine whether the relevant model could have routed a high-risk conversation to a different safety system, triggered a refusal or emergency escalation, restricted particular tools, required confirmation before an action, detected a minor user, reduced anthropomorphic behavior, or interrupted an interaction associated with a known hazard. The alternative would also need to be evaluated against the technology that actually existed when the relevant version was designed and released. Defendants can be expected to argue that a proposed safety measure was technically unavailable, unreliable, easily defeated, or incompatible with the legitimate functions of the system.
Failure to warn may provide a separate theory when a significant danger cannot reasonably be eliminated through design alone. The Utah Supreme Court has held that a manufacturer that knows or should know of a risk associated with its product may face strict liability when inadequate warnings render the product unreasonably dangerous. For an AI chatbot, disputed warnings might concern the system’s inability to diagnose or treat a condition, the possibility of fabricated information, the absence of human review, limitations on emergency use, or the risks of relying on personalized recommendations. A generic statement that an AI system “may make mistakes” will not necessarily answer whether users were adequately warned about the particular danger that caused the injury.
A traditional manufacturing-defect theory is less natural when the alleged product is continuously updated software rather than a physical object coming off an assembly line. A deployment-specific failure could nevertheless raise similar factual questions if one model release, configuration, safety layer, or account population operated differently from the developer’s intended specifications. A disabled classifier, omitted system instruction, defective update, or improperly deployed safety control could therefore matter even if the underlying architecture was reasonably designed. Determining the proper legal label would depend on how Utah courts ultimately classify the software and on what the technical evidence actually shows.
A Wrong Answer Is Not Enough: The Defect Must Cause an Injury
Product liability requires causation, not merely evidence that a chatbot produced something inaccurate or dangerous. The claimant must connect a specific alleged defect to the decision or event that produced the injury and then connect that event to compensable harm. Utah warning cases similarly require proof that the absence or inadequacy of a warning actually mattered to the outcome rather than identifying a warning problem in the abstract. If the same injury would have occurred regardless of the challenged design or warning, causation can fail even when the product could have been safer.
Consider a chatbot that provides a specific medication recommendation and dosage without obtaining information needed to identify a dangerous contraindication or interaction. A serious case would require the complete conversation, the model and application version, evidence showing how the recommendation was generated or permitted, and medical evidence establishing what happened after the recommendation was followed. Pharmacology or medical testimony may be needed to separate the chatbot’s alleged contribution from underlying disease, other medications, or unrelated causes. Utah’s current AI statutes themselves classify personalized medical advice capable of influencing significant personal decisions as a form of high-risk artificial-intelligence interaction, although that classification does not by itself establish civil product liability.
Mental-health interactions can present an even more complicated causation problem. A claimant may contend that the product was designed to reinforce a dangerous belief, encourage prolonged dependency, imitate human intimacy, or continue an interaction despite signals requiring a different safety response. The defense may respond that the injury resulted from an underlying condition, the conduct of another person, information outside the platform, or an independent decision that breaks the causal chain. Those disputes make complete conversation histories, medical evidence, expert testimony, prior incidents, safety testing, and the timing of design decisions potentially central to the case.
Not every chatbot dispute belongs in product liability. Utah’s Product Liability Act addresses personal injury, death, and property damage allegedly caused by defective products, while disputes involving only inaccurate information, disappointment, lost money, or offensive content may implicate very different legal doctrines. Depending on the facts, negligence, consumer-protection, warranty, misrepresentation, professional-liability, privacy, or contract theories may overlap with or replace a strict product-liability claim. The correct theory should follow the injury and the evidence rather than forcing every AI dispute into the same legal category.
Utah Already Regulates Certain AI Risks Directly
Utah has moved beyond treating generative AI as an entirely unregulated novelty. Current Utah law defines generative artificial intelligence and identifies certain personalized financial, legal, medical, and mental-health recommendations as high-risk AI interactions. Utah Code section 13-77-102 also provides that it is not a defense to a violation of consumer-protection law that generative AI made the offending statement, performed the offending act, or was used in furtherance of the violation. Separate disclosure requirements apply in consumer transactions and in specified high-risk interactions involving regulated occupations.
Utah has enacted more specific provisions for mental-health chatbots. Those provisions require covered mental-health chatbots to disclose clearly that the user is interacting with artificial intelligence rather than a human and impose protections concerning user information and certain advertising practices. Utah Code section 58-60-118 also creates an affirmative defense to particular professional-practice enforcement actions when a supplier develops, files, follows, and documents a qualifying safety policy. The required policy addresses issues such as model and training-data documentation, safety testing, foreseeable harmful interactions, real-time protocols for acute physical danger, regular safety review, user understanding of system limitations, and prioritizing user mental health and safety over engagement metrics or profit.
That detailed affirmative defense is important, but it should not be overstated. Section 58-60-118 expressly limits the defense to specified administrative or civil actions involving particular professional-practice provisions, so it is not a blanket immunity from ordinary personal-injury or product-liability claims. At the same time, the statute identifies categories of technical and corporate evidence that could become highly important when a Utah user alleges that a chatbot caused a serious mental-health injury. Safety testing, foreseeable adverse outcomes, incident-response procedures, internal documentation, and the relationship between safety and engagement are exactly the kinds of subjects that sophisticated AI-injury discovery is likely to examine.
Utah’s Legislature has also amended the Product Liability Act itself to create special rules for certain Level 4 and Level 5 automated-driving systems. Those 2026 provisions include requirements concerning reasonable feasible alternative designs and comparisons between automated-system and human injury rates, along with a separate state-of-the-art defense for covered automated-driving systems. Those provisions apply to the automated-driving systems described by the statute, not ordinary conversational chatbots. Their existence nevertheless demonstrates that Utah lawmakers know how to create technology-specific product-liability rules when they choose to do so, which is another reason courts should not simply import the automated-vehicle standards into unrelated AI cases.
Digital Evidence May Determine Whether an AI Injury Claim Can Be Proven
The user’s own records can be as important as the final harmful response. A serious investigation should preserve the complete conversation, available account exports, screenshots showing timestamps and edits, account settings, application and device information, subscription records, notifications, and other material showing exactly how the interaction unfolded. Saving only the most damaging sentence can create problems if earlier prompts later become relevant to causation, foreseeability, or a defense allegation that the system was intentionally manipulated. When the injury is severe, the original account and device may also need to be preserved rather than altered, deleted, or casually surrendered to the company.
The platform may possess an entirely different layer of evidence. Relevant material can include the specific model version, system instructions, safety policies, red-team results, known incident reports, classifier thresholds, age-control systems, release notes, safety bug reports, escalation logic, internal risk analyses, A/B experiments, engagement metrics, and communications about hazards identified before the injury. Because modern AI products can change rapidly, the system available months later may not behave like the version involved in the incident. Early preservation therefore matters even when formal discovery will be needed to obtain much of the evidence from the developer.
The damages side of the case needs equally disciplined documentation. Emergency treatment, hospitalization, imaging, medication records, specialist evaluations, psychological or psychiatric treatment when relevant, wage documentation, future-care evidence, and testimony concerning changes in function may all become important. The defense may examine prior medical and mental-health history closely in an effort to identify alternative causes, making accurate chronology more useful than trying to hide inconvenient facts. A technically strong defect theory will not carry a personal-injury case unless the medical and damages evidence establishes what the alleged defect actually caused.
Expert testimony may bridge the technical and medical portions of the case. An AI or software expert may need to explain the precise failure mechanism and whether a proposed alternative safety design was genuinely feasible, while human-factors expertise may matter to warnings, reliance, or interface design. Medical experts may then have to determine whether the chatbot-associated event caused or materially contributed to the claimed physical or psychological injury. The strongest cases connect those disciplines into one coherent causal explanation rather than treating the chatbot transcript as self-proving.
What the AI Company and Its Insurer Are Likely to Argue
The first defense may be that there was never a “product” in the legal sense. The company may characterize the chatbot as a service, a communications platform, software, information, or expressive content and may raise constitutional or other defenses when the claim focuses on generated language. The Garcia decision gives plaintiffs a developing response by distinguishing functional design choices from the ideas or expressions generated through the application, but that decision does not bind Utah courts. A Utah complaint should therefore identify the allegedly defective design with enough precision that the claim does not depend entirely on calling particular words defective.
The defense may next focus on warnings, terms of use, alleged misuse, unusual prompting, inaccurate age information, ignored safety messages, or third-party software that changed how the underlying model behaved. Utah has long permitted product misuse and assumption-of-risk issues to affect strict-liability cases, and the Product Liability Act expressly addresses later alterations or modifications that change a product’s intended purpose, use, function, design, or manner of use. Those principles make preservation of the entire interaction especially important. They do not mean that every unconventional use eliminates a claim, because foreseeability and the actual causal significance of the user’s conduct remain factual questions.
Causation will often receive an equally aggressive attack. Defense experts may attribute an injury to a preexisting condition, another source of information, independent human conduct, later events, or a decision that allegedly cannot fairly be attributed to the chatbot. A plaintiff who merely produces a disturbing transcript without addressing those alternative explanations gives the defense substantial room to separate the alleged defect from the injury. Building the chronology early allows the medical, technical, and factual evidence to be evaluated together rather than allowing the defense to construct the only complete causal narrative.
The company or its liability insurer may also try to frame the incident as user error before the claimant has access to the technical evidence needed to evaluate that assertion. A request for a broad statement, unrestricted account access, extensive authorizations, or a quick settlement can appear routine while the developer retains far more information about the product than the injured person possesses. Serious AI injury claims should be valued only after the relevant product version, potential defendants, medical prognosis, damages, coverage, liens, defenses, and release terms are understood. Preserving evidence promptly does not require settling promptly.
Utah’s Product Liability Deadline Makes Delay Risky
Utah’s Product Liability Act contains a specific two-year limitations period. Section 78B-6-706 provides that an action under the Act must be brought within two years after the claimant discovered, or through due diligence should have discovered, both the harm and its cause. Determining when that occurred can itself become disputed when the causal connection was not apparent immediately. Other potential causes of action may have different deadlines, which is another reason the timing analysis should be performed from the facts of the particular case rather than from a general assumption about personal-injury statutes.
The practical evidence deadline may arrive much sooner than the legal deadline. AI models are replaced, safety layers are changed, user interfaces are redesigned, conversations can disappear, account settings can change, and internal technical records can be overwritten or become harder to identify. A claimant should preserve available evidence without altering, fabricating, reverse-engineering, or improperly accessing material that is not theirs. Counsel can then determine what additional platform information should be preserved and pursued through appropriate legal procedures.
When a Serious AI-Related Injury Deserves Legal Review
A potential chatbot product-liability case deserves serious investigation when there is a measurable injury, a documented interaction with the system, a plausible safety defect, and a reasonable causal connection between the defect and the harm. The case becomes more significant when the interaction involved a foreseeable high-risk use, evidence suggests the developer already knew about the hazard, or a technically feasible safety measure could have prevented or reduced the injury. By contrast, an inaccurate output without injury or an identifiable causal mechanism is much less likely to support a traditional Utah product-liability claim. Careful investigation can also determine whether negligence, consumer-protection, professional-liability, warranty, or another theory fits better than strict products liability.
These cases will likely be fought over product classification, software architecture, warning adequacy, foreseeability, causation, and access to information held by the developer. That makes them poor candidates for quick evaluation based only on a few screenshots or an insurer’s initial characterization of what happened. Gabriel K. White and The Legal Beagle can evaluate serious Utah injuries involving defective products and emerging digital-product theories with a litigation-focused approach. Call The Legal Beagle at (801) 915-6152 or contact the firm at https://www.mylegalbeagle.com/contact.




Comments