top of page

Failure to Warn in the AI Era: Can AI Companies Be Held Liable When Their Products Cause Predictable Harm?

2 days ago
10 min read

Yes. An AI company can potentially be held liable when an AI system causes foreseeable physical or psychological harm, but there is no single established “AI liability” rule that decides every case. In Utah, the viable theory may depend on whether the system is legally treated as a product, a service, or both, and whether the claim concerns an inadequate warning, unsafe design, negligent operation, or another recognized tort. A claimant still must prove the elements of the particular claim, including causation and compensable harm. A disturbing or wrong AI response, standing alone, does not establish liability.


Generative AI does not fit neatly into legal categories developed for ladders, prescription drugs, vehicles, and industrial machines. A cloud-based chatbot can look like a standardized product to its user while being delivered through a continuously changing online service. Utah appellate law already creates a significant threshold issue: in Legal Tender Services v. Bank of American Fork, 2022 UT App 26, the Utah Court of Appeals held that an online payment portal was a service rather than a product for product-liability purposes. That does not decide how Utah courts will classify modern AI, but it means an AI injury case should not be built on a single theory. Justia Law


Utah has also begun regulating AI in ways that recognize concrete risks from automated interactions. Current law requires specified disclosures in some generative-AI consumer and professional interactions and imposes more specific rules on mental-health chatbots used by Utah users. Those statutes regulate particular conduct and do not automatically establish the elements of a private personal-injury claim. They do, however, show that AI transparency, reliance, and safety are already subjects of Utah law rather than abstract future concerns. Utah Legislature


A serious AI injury case therefore looks less like a complaint about “bad information on the internet” and more like a conventional injury investigation applied to a new technology. The important questions include what risks the company knew or should have known, whether the interface encouraged foreseeable reliance or dependency, what safeguards were technically available, what warnings actually reached the user, and whether a different warning or design would have changed the outcome. Those issues may require internal company records, software and human-factors experts, medical evidence, and complete preservation of the user’s interactions. A screenshot of one troubling answer rarely establishes the whole causal story.


What Failure to Warn Means Under Utah Law


Utah failure-to-warn law starts with a familiar principle: a manufacturer can face strict liability when it knows or should know of a product risk and the absence or inadequacy of a warning makes the product unreasonably dangerous. Utah Code section 78B-6-703 likewise centers a product claim on a defect or defective condition that existed when the manufacturer or initial seller sold the product and that made it unreasonably dangerous. Utah’s model jury instructions describe an adequate warning as one that reasonably catches the user’s attention, is understandable to foreseeable users, fairly communicates the danger associated with foreseeable use, and is conspicuous enough for the magnitude of the danger. The Utah Supreme Court’s decision in House v. Armour of America, 929 P.2d 340 (Utah 1996), also makes causation essential. The plaintiff must connect the inadequate warning to the injury by showing that an adequate warning would have changed use or precautions. Utah Legislature


That framework becomes difficult when an AI company relies on a generic statement such as “AI can make mistakes” or “this is not a human.” A warning about factual errors may not address a different alleged risk, such as emotional dependency, unsafe medical reliance, encouragement of self-harm, dangerous instructions, or reinforcement of a vulnerable user’s beliefs. On the other hand, a prominent and specific warning delivered at the relevant moment can become important defense evidence if it fairly addresses the danger that occurred. Warning adequacy therefore turns on content, placement, timing, audience, and the magnitude of the risk, not merely whether some warning appeared in terms of service.


The First Utah Problem: Is AI a Product or a Service?


The threshold question in Utah may be whether the AI system is a “product” at all. In Legal Tender Services v. Bank of American Fork, the Utah Court of Appeals held that an online payment portal did not qualify as a product because it was not a movable good or tangible personal property and the transaction was predominantly for services. The court emphasized that a service alone cannot be a product under Utah product-liability law. A subscription chatbot or cloud AI assistant has obvious similarities to an online service, giving an AI defendant substantial Utah authority for challenging a strict product-liability theory. Justia Law


That threshold ruling would not necessarily resolve every possible negligence claim, but simply relabeling a defective-product theory as “negligence” is not a reliable way around Utah product-liability law. A genuinely separate negligence theory may focus on service conduct, human safety review, escalation decisions, or another duty that exists independently of a product defect, and it must satisfy its own duty, breach, causation, and damages requirements. The distinction matters because Utah courts examine the substance of the alleged wrongdoing rather than the label placed on a cause of action. The complaint and evidence should therefore separate alleged product defects from allegedly negligent operational conduct. Justia Law


What the Character.AI Case Shows—and What It Does Not


A federal case involving Character.AI shows how another court approached the problem. In Garcia v. Character Technologies, a Florida federal judge allowed product-liability and failure-to-warn claims to proceed past the motion-to-dismiss stage and treated the Character.AI app as a product to the extent the claims targeted alleged defects in the application rather than ideas or expressions in chatbot output. The alleged defects included age controls, reporting mechanisms, anthropomorphic design choices, and content-control features. The ruling applied Florida law, arose at an early pleading stage, and is not binding on a Utah court. CourtListener


Garcia also did not produce a final ruling that the defendants were liable. Character.AI and Google agreed to settle the lawsuit in January 2026, and the terms were not publicly disclosed. A settlement does not establish defect, negligence, causation, or damages, and it does not determine whether another court would classify a different AI system as a product. The case is useful because it shows that traditional product and warning theories can survive an initial challenge in some AI litigation, not because it creates a nationwide rule of AI liability. Investing.com


Utah Is Already Regulating AI Warnings and High-Risk Interactions


Utah’s own statutes make the local picture more concrete. Utah Code section 13-77-102 provides that, for statutes administered and enforced by the Division of Consumer Protection, it is not a defense that generative AI made the violative statement, undertook the violative act, or was used in furtherance of the violation. Section 13-77-103 requires specified AI disclosures in consumer transactions when a consumer clearly asks whether AI is being used and imposes prominent disclosures for certain high-risk AI interactions in regulated occupations. The chapter defines high-risk interactions to include certain personalized financial, legal, medical, and mental-health recommendations that could reasonably be relied on for significant personal decisions. Utah Legislature


Utah separately regulates mental-health chatbots. Section 13-72a-203 requires a supplier to clearly and conspicuously tell a Utah user that a covered mental-health chatbot is AI and not human before access, after specified periods of inactivity, and when the user asks whether AI is being used, while section 13-72a-204 gives the Division of Consumer Protection enforcement authority. A 2026 provision also creates an affirmative defense in specified professional-licensing proceedings for certain suppliers that maintain detailed safety policies addressing matters such as reasonably foreseeable adverse outcomes and acute risks of physical harm. These rules are not a general private tort standard or automatic path to civil recovery, but they make foreseeability, disclosure, and safety practices concrete Utah regulatory issues. Utah Legislature


Section 230 and the First Amendment Are Not Simple Answers


Section 230 of the federal Communications Decency Act will also appear in many internet-liability disputes, but it should not be reduced to the slogan that “internet companies cannot be sued for content.” The statute generally prevents an interactive computer service from being treated as the publisher or speaker of information provided by another information content provider. It also defines an information content provider as a person or entity responsible, in whole or in part, for creating or developing the information at issue. How those provisions apply when a company’s generative system produces the challenged output, or when the claim targets design and safety features rather than third-party speech, depends on the theory and remains an important developing question. U.S. Code


The First Amendment can create a separate defense when liability is sought because of speech or expressive content. In Garcia, the district court declined at the motion-to-dismiss stage to hold that Character.AI output was protected speech, but that was not a final appellate resolution. Future courts may distinguish claims attacking ideas or expression from claims attacking nonexpressive features such as age verification, safety escalation, notification systems, or engagement architecture. A Utah case should be developed with that distinction in mind rather than assuming either that constitutional protections always bar an AI injury claim or that they never apply. CourtListener


Proving Predictable Harm Requires the Right Evidence


Foreseeability is likely to be one of the central factual battles. An AI company may possess red-team results, trust-and-safety reports, user complaints, incident databases, moderation escalations, model evaluations, child-safety testing, or internal research identifying recurring hazardous interactions before the plaintiff’s injury. Public safety statements, model cards, release notes, policies, and design history can help reconstruct what the company understood and when, although the admissibility and significance of later changes require careful analysis. The goal is to establish the risk landscape that existed when the relevant version of the system was deployed to the injured user.


The user-side evidence matters just as much. Complete chat histories, exported account data, screenshots, screen recordings, emails, push notifications, account settings, age information, parental controls, device logs, billing records, and the warnings actually displayed may help show what the user experienced. Context matters because the defense will examine the full sequence for alternative causes, intervening events, warnings, and user choices rather than accept selected screenshots at face value. If the platform permits deletion or editing, preservation should address both the user’s copies and discoverable information held by the company.


The technology itself is versioned evidence. Model names, system prompts, safety classifiers, fine-tuning changes, A/B tests, account flags, moderation events, escalation records, interface versions, and software-update dates may matter because the system encountered by the injured user may not exist in the same form months later. Unlike a failed ladder or machine, a cloud AI service can change without leaving the claimant with a physical artifact to preserve. That makes timely preservation letters, targeted discovery, and technically informed inspection protocols unusually important.


Causation and Damages Still Control the Case


Causation will often be harder than proving that a dangerous interaction occurred. The defense may argue that the user would have acted the same way with a stronger warning, that independent human decisions caused the harm, that the user ignored safety messages, that the risk was obvious, or that another medical or psychological condition explains the outcome. In a case involving psychiatric injury, self-harm, or death, medical records and qualified expert testimony may be necessary to connect the alleged failure to the injury. The plaintiff’s case has to establish the actual causal sequence rather than relying on the novelty or emotional force of the technology.


Damages require the same discipline. Depending on the injury, proof may include emergency treatment, hospitalization, counseling or psychiatric care, medication, rehabilitation, lost income, diminished earning capacity, future treatment needs, and the effect on ordinary life and relationships. A death may support a wrongful-death claim with its own parties, damages, and procedural requirements under Utah law. Shocking chatbot language may be important evidence, but it does not substitute for documentation of legally recoverable loss.


How AI Companies and Insurers Will Defend These Claims


AI defendants, insurers, and defense counsel can be expected to attack multiple parts of the case at once. They may argue that the system is a service rather than a product, that the danger was not foreseeable, that terms of service or on-screen warnings were adequate, that user choices or third parties broke the causal chain, that the medical connection is unsupported, or that federal law and constitutional protections limit the claim. They may also seek broad medical, social-media, device, and account discovery to develop alternative-causation arguments. A claimant should understand those issues before giving detailed statements, signing broad authorizations, accepting money, or agreeing to a release.


Coverage may be less visible than in an automobile case, but it can still affect claim strategy. A technology company may have commercial liability, technology errors-and-omissions, excess, or other potentially relevant coverage, and contracts among model providers, cloud vendors, developers, and business partners may allocate defense or indemnity obligations. Whether any policy or contract applies depends on its language, exclusions, pleaded theories, and facts. A serious claim should not be valued around an early offer before the responsible entities, available coverage, damages, liens, and release language are understood.


Utah Deadlines Make Early Preservation Important


Timing matters because Utah’s Product Liability Act has a specific limitations provision. Utah Code section 78B-6-706 states that an action under the Act must be brought within two years from when the claimant discovered, or through due diligence should have discovered, both the harm and its cause. Other claims may have different limitation periods, and particular defendants or circumstances can create additional notice or timing rules. Deadlines should be analyzed from the actual facts instead of assuming that a general civil limitations period controls an AI-related injury. Utah Legislature


Delay can damage the evidence before any filing deadline arrives. Chat logs can be deleted, accounts can close, safety systems can be revised, model versions can be retired, interface language can change, employees can leave, and operational data can disappear under ordinary retention practices. Prompt investigation does not mean filing a weak lawsuit or rushing toward settlement; it means preserving enough evidence to determine whether the harm was predictable, whether the company had a realistic opportunity to reduce it, and whether a legally sufficient causal connection can be proved. In this area, preserving the system’s state may be as important as preserving a physical product after an accident.


When an AI Harm Claim Deserves Serious Investigation


Not every disturbing or inaccurate AI interaction creates a viable personal-injury claim. The cases that justify serious investigation are more likely to involve substantial injury or death, an identifiable and foreseeable risk, evidence of what the company knew or should have known, and a plausible warning, safeguard, or operational response that could have changed the outcome. Utah’s unresolved product-versus-service question makes careful claim selection especially important, because the legal theory must match the architecture and business model of the specific system. The novelty of AI does not eliminate ordinary requirements of proof.


If an AI system appears to have contributed to a serious injury or death in Utah, preserve the account and communications before the platform changes and obtain advice before surrendering data, giving a recorded statement, or signing a broad release. Gabriel K. White and The Legal Beagle evaluate serious Utah personal-injury, product-liability, and wrongful-death matters from the plaintiff’s side, with direct attorney involvement and a focus on evidence that can survive litigation rather than merely support an early demand. A proper evaluation should examine classification, warnings, design, foreseeability, causation, damages, insurance, and preservation together. Call The Legal Beagle at (801) 915-6152 or contact the firm at https://www.mylegalbeagle.com/contact

Comments


©2024 All Rights Reserved By My Legal Beagle.

bottom of page