
A federal court just ruled your chatbot's output is a "product." Strict liability now applies — and Section 230 won't save you.
Here's what that quietly changes for every enterprise running AI.
Under strict product liability, a plaintiff doesn't have to prove you were negligent. They only have to prove the output was defective. The "we took reasonable care" argument that protected software for 30 years doesn't reach this.
The one defense that survives is older than AI: reasonable alternative design. You have to show, with documented evidence, why your system was built the way it was — what you considered, what you rejected, and why the safer architecture you're accused of ignoring wasn't actually safer.
That evidence doesn't come from a dashboard. Governance platforms like Credo AI and IBM watsonx.governance monitor and report on a system after it exists. They don't architect it, and they can't manufacture a design record for decisions that were never made.
And the clock is loud. As of Feb 2026 there are 2,200+ active AI and platform liability cases. ISO's new CGL endorsements (CG 40 47 and CG 40 48) now let carriers exclude generative-AI claims outright — unless you can show documented governance. Carriers like W.R. Berkley are applying "absolute" AI exclusions to D&O and E&O too — the coverage that protects officers personally. The EU Product Liability Directive classifies software as a product on Dec 9, 2026.
The takeaway for legal and engineering teams: your AI defense isn't written after an incident. It's built into the architecture before one. The audit trail, the design rationale, the insurance evidence — they're engineering artifacts, not legal afterthoughts.
Save this for the next AI risk review with your GC. And a question for the legal teams here: can your current AI vendor hand you a design-rationale record today, or only a monitoring dashboard?
#AIProductLiability #AIGovernance #LegalTech #EnterpriseAI #AICompliance