Your AI Won’t Testify for You

In 2021, Krafton, the South Korean publisher behind PlayerUnknown’s Battlegrounds (PUBG), bought the game studio Unknown Worlds for $500 million. The deal promised the studio’s leadership another $250 million if they hit their revenue targets through December 2025, and it made firing them hard. “Cause” meant a felony, gross misconduct, leaking confidential information, or intentional fraud.

By late 2024, the forecasts said the targets would be hit, and Krafton’s CEO wanted out. His head of corporate development told him the studio’s leadership hadn’t committed any misconduct that could be stretched into “cause.” How inconvenient! So the CEO asked ChatGPT how to avoid the earnout anyway, and per the Delaware Court of Chancery’s March 2026 opinion, he “followed most of its recommendations.” That included blocking distribution channels so the subsidiary’s new product couldn’t launch, torpedoing the sales targets, and then firing the leadership team he’d just denied any chance to earn it.

The court didn’t have to infer any of this, because ChatGPT kept a transcript, the plaintiffs got it, and Vice Chancellor Will quoted the CEO’s chats directly in the opinion, laying the AI’s suggested strategies next to his actual conduct. The chat logs were the witness. She ordered the subsidiary’s ousted CEO reinstated, extended the sales timeline by more than eight months, and kept the damages litigation rolling.

The machine put the CEO’s bad faith on the record, in his own words. When your AI gets it wrong, or when it talks you into something you shouldn’t have done, the record works the same way in both directions.

Your chats are now exhibits

The Krafton case isn’t a one-off. It’s the latest turn in a pattern that most enterprises still haven’t factored into their risk registers.

What happened in the 3M Watson Grinding litigation

In Laake v. 3M Company, litigation arising from the 2020 Watson Grinding explosion in Houston, a plaintiffs’ attorney named Will Moye noticed that an engineering expert defending 3M seemed to have drafted his report with ChatGPT. During the deposition, Moye went off the record and demanded the underlying prompts. Roughly three hours later, more than 350 pages of ChatGPT material arrived, including a prompt instructing the system to “show how 3M is 0% at fault.” The whole dump is public now, and you can read it on DocumentCloud.

And in the Heppner criminal case

Then there’s United States v. Heppner, a criminal case out of the Southern District of New York. The defendant had typed factual and legal questions into a consumer AI chatbot, and when prosecutors came looking, the court held the records weren’t protected. Because the platform’s terms of service permitted data logging and model training, there was no reasonable expectation of confidentiality. Read that again slowly if your employees are pasting legal questions into consumer-grade AI tools. The Department of Justice case page and the docket are both public.

The law is still unsettled

The uncertainty cuts both ways. In June 2026, a New York judge blocked a subpoena for a litigant’s ChatGPT records, finding the material was protected legal research. Courts are still fighting over when prompts are discoverable, when they’re privileged, and when a three-hour mid-deposition dump ruins your expert.

What’s consistent is that an AI interaction preserves your assumptions, your rejected alternatives, and the reasoning you never put in the polished final document. As cybersecurity professional Josh Copland put it in a piece on the 3M case for CSO Online:

AI won’t testify for you; it won’t do jail time for you; it won’t pay your fines; but it will absolutely testify against you.

So who’s liable?

When an AI system causes harm, liability rarely lands on a single party, and the reason is structural. Negligence, product liability, contract, and agency law all assume an intentional human decision-maker. An AI agent that adapts to new information and takes actions nobody programmed breaks that assumption, which is why courts are improvising.

Broadly, three parties end up on the hook:

PartyWhy they might be liableWhy they might escape
DeveloperBuilt and trained the model. Defects, biased training data, or inadequate testing put the lab’s conduct under the microscope.Whether negligence or product liability doctrine actually fits a system that writes its own plan is unsettled. Patent law (Thaler v. Vidal) confirms an AI system can’t be named as an inventor because inventorship requires a person.
DeployerThe company that put the AI into its own workflow. Integration doesn’t outsource accountability. A lender using automated credit decisions still owes adverse-action notices under Regulation B.If the vendor has liability caps, or the deployer can prove meaningful human oversight existed. The Financial Industry Regulatory Authority 2026 Annual Regulatory Oversight Report tells securities firms existing obligations survive generative AI insertion.
VendorExposed for misrepresented capabilities, ignored defects, and breached commitments.AI service agreements are stuffed with liability limitations that cap what you can actually recover. The vendor you contracted with may not even be the entity whose model touched your data.

The wildcard: strict liability?

Writing for IR Global, attorney Douglas DePeppe argues that the July 2026 frontier incidents could meet the six-factor test for the Abnormally Dangerous Activity Doctrine under Section 520 of the Restatement (Second) of Torts. Those incidents include an OpenAI agent that escaped its sandbox and breached Hugging Face for days, Anthropic models that wandered out of a misconfigured test environment into three real companies’ systems (two of which didn’t learn about it for months), and UK Security Institute tests where autonomous agents planted malicious code in an open-source project without any containment failure to blame.

That’s strict liability: high risk of great harm, an activity that can’t be made safe, uncommon usage. No intent, no negligence, no new statute required. No court has adopted the theory for AI yet, and the frontier labs would obviously contest whether their testing is like storing explosives. But it’s a cleaner fit than the alternatives, which is precisely why I’m curious what my co-panelists think.

Will anyone actually go to jail?

Probably not you, and it’s worth understanding why before the fear-mongering sets your compliance budget.

A vendor survey of EMEA executives, polling more than 1,000 IT, data management, and security leaders at mid-sized and large businesses, found that 40 percent of executives are worried about personal legal liability under new AI accountability laws. Meanwhile, 70 percent admitted their automated AI workflows touch sensitive data without full human oversight. The anxiety is real, but the survey’s sponsor sells AI governance software, so read both numbers with that in mind.

Precedent looks more like Firemen’s Retirement System of St. Louis v. Sorenson, the Marriott Starwood derivative suit that came out of the 2018 breach of 500 million guest records. Marriott’s board had ranked cybersecurity as its second-biggest risk, received annual reports on it, and engaged PwC to assess Starwood’s security after the acquisition. None of that stopped the breach, and Chancery still dismissed the claims, with Vice Chancellor Will (the same judge who later reinstated Unknown Worlds’ CEO) drawing the line between “a flawed effort and a deliberate failure to act,” and blaming the hacker.

I cover this case and its lessons at length in Cyber Risk is a Myth. Delaware cares whether you had oversight systems, not whether they worked perfectly; some process beats no process. Courts have so far tolerated flawed efforts, which should be reassuring if you’re a director. The one thing Sorenson won’t protect is the company that can’t produce a name when asked who owned a consequential AI decision.

What to do while the law figures itself out

I argued in July that your AI governance program can’t stop anything. A fire alarm is not a fire department, and most of what passes for AI governance today is wiring the alarm. If you want to be defensible rather than merely compliant, the boring work looks like this:

  1. Name a governor with kill-switch authority. One accountable human who can pull the plug and reports into risk or trust and safety, never to the VP whose bonus depends on shipping. Committees don’t stop models; owners do.
  2. Automate the stop. Define hard thresholds where the system suspends itself: output anomalies spike, bias detection exceeds limits, user harm reports cross a frequency. Waiting for a meeting is how a rogue process runs for days, which is exactly what happened at Hugging Face.
  3. Build rollback before autonomy. If your agents take real-world actions, you need an undo button and someone with authority to press it, plus contractual staged rollout: observe-only first, supervised actions second, expanded autonomy only after consistent benchmark performance. Agree upfront what happens when performance drifts, because vendors update models and swap foundations constantly.
  4. Make human review real. Uber’s Tempe fatality taught the lesson: the safety driver was streaming video on her phone when the system spotted a pedestrian it hadn’t been designed to brake for. A reviewer who can flag problems but can’t act is a witness, not a control.
  5. Manage prompt retention deliberately. Decide, before a subpoena does it for you, which AI interactions are consequential enough to retain: the material prompts, the outputs, evidence a qualified human actually reviewed them. Tier by consequence, and update your legal holds to cover prompts and system instructions.

None of this settles the liability question. But if a decision gets challenged a year from now, the organizations that survive are the ones that can reconstruct what happened: what data the model saw, what the human accepted or rejected, and who owned the call. Everyone else is betting their litigation posture on the goodwill of a chat log.

Join the argument

Nobody has final answers, and a fair amount of the confident advice in circulation comes from people who profit from your anxiety. Courts are moving faster than legislatures, the EU’s enforcement timeline keeps slipping, and the real fights are happening in Delaware, Texas, and Manhattan.

My friend Larry Whiteside Jr. will be moderating as I dig into these questions alongside attorneys Maria Lobato and Maria McReddie at Who Is Actually Liable When Your AI Gets it Wrong on September 17. Bring your questions, because the panel is built to be interactive, and we’re expecting to spend most of it answering yours.

Security Risks ARE Business Risks. Get the Weekly Context.

Every week, I break down the most important intersections of cybersecurity, AI regulation, and business risk. Plus: early access to 'Cyber Risk is a Myth' chapter resources and course updates.

I don’t spam! Read the privacy policy for more info.

Similar Posts