
I spent early client engagements thinking the monitoring layer was the defense. Log what the AI does, track the outputs, surface the flags, run the dashboard — that was the governance story we told. Then I reviewed the audit infrastructure a client's legal team had built and I saw a different story. Every failure the system had produced — every inconsistent output, every flagged decision — was documented in meticulous detail. That documentation was their compliance evidence. It was also exactly what opposing counsel would subpoena in an AI product liability claim, not as evidence of good governance, but as a log of every time the system had been wrong and the company had known about it.
The January 2026 Character.AI ruling established what I had started to believe was already true: AI output is a product. Strict liability applies. Section 230 doesn't protect you. The architecture is now the defense — and the audit trail is the prosecution's exhibit list.
What the 2026 Rulings Did to Every GC Conversation I Was Already Having

My briefings with general counsels changed after January in a way that was more abrupt than I'd expected. The case doing the most work in those conversations is Character.AI — the M.D. Florida court that denied both Section 230 and First Amendment defenses by ruling the chatbot was "a product for the purposes of plaintiff's claims arising from defects in the app rather than ideas or expressions within the app." Google and Character.AI settled with families across four states, but the product classification stands. What I tell GCs now is that the threshold question has changed: not "did we supervise the AI?" but "did we design it for safety?" Those questions have different answers and very different documentation requirements.
Nippon Life v. OpenAI followed in March — a $10.3 million suit in the Northern District of Illinois where ChatGPT had drafted over 44 court filings with fabricated case citations. The claim doesn't turn on negligence. It turns on what the AI output did in the world. And Bouck v. Meta found that Section 230 immunity fell once the platform acquired actual knowledge of fraudulent AI-generated content — which makes "actual knowledge" a discoverable question in every AI-related litigation going forward.
The burden of proof in product liability is different from negligence. Plaintiffs don't need to show you were careless. They need to show the product was defective. Your defense requires showing you considered a safer design alternative and chose against it — at design time, not after a claim was filed.
The distinction between those two timeframes is everything. It's the thing I now lead with in every GC briefing.
The Insurance Renewal That Changed How I Open Engagements

I was in an underwriting meeting with a client who had done everything the governance frameworks asked — compliance reports, audit summaries, a Credo AI dashboard, documented model monitoring. The underwriter looked at all of it and asked a question I hadn't anticipated: did the client have pre-deployment architectural decision documentation? Not what the system had done since it shipped. What decisions the engineering team had made before it shipped, and why.
My client didn't have it. Their compliance team had extensive records of what the AI had done. Nothing recorded what the engineers had decided before the first model went live.
They didn't get an AI endorsement that cycle. They got CG 40 47 — the ISO CGL endorsement Verisk released in January 2026 that excludes generative AI claims from commercial general liability coverage. CG 40 47 removes Coverage A and B. CG 40 48 removes Coverage B only. Both are being adopted in standard renewals. W.R. Berkley has moved to absolute AI exclusions across D&O, E&O, and Fiduciary Liability, eliminating coverage for any claim "based upon, arising out of, or attributable to" AI use or deployment.
What changed after that meeting is where I start every engagement now. The architectural decision log is the first artifact we deliver — before architecture diagrams, before data schemas, before any model evaluation. It exists because if there's a claim two years from now, we need that documentation to have been written by the engineers at the time they made the decisions, not reconstructed from change logs after the fact.
The Gap No Governance Platform Can Close

I've worked alongside Credo AI, IBM watsonx.governance, and OneTrust deployments in enough engagements to say this fairly: they do something genuinely useful. They monitor deployed models, surface bias metrics, track compliance status, generate audit reports. Credo AI raised $45 million on that value proposition and made Fast Company's Most Innovative Companies list in 2026. The demand reflects real value.
The gap isn't what they do. It's what they can't do retroactively: they can't create pre-deployment evidence. What I've come to understand is that their value starts at deployment. The documentation that product liability defense requires predates deployment by months — the architectural choices, the safety tradeoffs, the alternatives the team considered and rejected. That record has to be built when those decisions are being made.
The Judge Rakoff ruling in February 2026 adds a wrinkle I now flag for every legal team. Consumer Claude usage without direct attorney supervision isn't privileged. If your legal team has been using AI tools to draft governance strategy without formal attorney oversight, those outputs are discoverable. The platform monitoring your AI doesn't protect the process your team used to build its governance approach.
I've started asking clients a different set of questions: not "which platform did you buy?" but "what documentation did your engineers create at design time, and can it withstand a discovery request?" Those are different questions with very different answers. The AI product liability defense work we do at Veriprajna starts from that gap — not from the governance layer, but from the architectural layer that predates it.
The Agentic Deployment Where We Had to Stop and Rethink

The agentic problem caught me off-guard — not because the concept was surprising, but because the specific liability shape was different from what I'd been working with.
I was deploying an agent with a defined set of tools: query databases, draft documents, send emails on behalf of users. Standard scope. But when I looked at the liability exposure through the product liability lens, the calculation changed. An agent that takes external actions — files something, communicates something, triggers a payment — isn't just generating output. It's a product that acts in the world. The "as is" disclaimer in the standard contract was written for software that generates text. It wasn't written to disclaim the consequences of an email sent without human review.
Clifford Chance identified this "liability gap" in standard contracts applied to agentic systems — the disclaimer language doesn't extend cleanly to autonomous action. Singapore's IMDA released a draft Agentic AI Governance Framework in January 2026 specifically because the existing governance frameworks hadn't caught up.
We stopped the deployment and redesigned. Every tool and action class the agent could invoke got a written authorization document: a contemporaneous record that a human had explicitly decided this action type was within scope, with the scope boundaries defined. That document exists because the reasonable alternative design defense requires showing that the agent's action scope was a deliberate architectural choice, made with alternatives considered, not an accidental capability that nobody scoped.
How Every Engagement Starts Now

The three legislative deadlines I use to make the urgency concrete are all landing in the same window. The EU Product Liability Directive 2024/2853 requires transposition by December 9, 2026 — software and AI are now products under strict liability across EU member states, no negligence proof required. The EU AI Act's high-risk requirements hit August 2, 2026, with fines up to EUR 15 million or 3% of global turnover. Colorado's SB 205 goes to enforcement June 30, 2026 at $20,000 per violation.
Colorado's affirmative defense is worth noting. Companies with documented governance frameworks can claim it. The defense exists in the statute precisely because documented pre-deployment architecture is what the legislature decided distinguishes defensible from indefensible — not just in a court's opinion, but in the law itself.
The AI LEAD Act — the bipartisan Durbin-Hawley bill from September 2025 — would add a federal strict liability cause of action where even companies that took "all possible care" aren't shielded. Design defects, failure to warn, breach of warranty. Rights can't be waived via terms of service.
What this means practically for how I structure the beginning of an engagement: the architectural decision log template is the first deliverable, before any code. Every safety tradeoff — why this retrieval architecture, what alternatives were considered for the data layer, what the team decided about output constraints — gets a contemporaneous record from the engineer who made the call.
For agentic systems, there's a scope authorization document for each action class before the agent touches a staging environment. The impact assessment is a staging prerequisite, not a production prerequisite — the decisions that will matter in litigation are already locked by the time you reach production.
The companies navigating the 2026 liability shift from a defensible position share one thing: their engineering leads treated design documentation as a legal artifact from day one. Not a compliance program layered on after the system was built. A different understanding of what the work product is.
The full picture of what this looks like in practice is at Veriprajna's AI product liability defense practice. But the architecture question has to be answered by engineers, not by platforms. What I keep coming back to: if there's no pre-deployment record of the decisions your team made, there's no defense — only a very detailed account of what the system did while no one was building the case.