Skip to main content

Attorney for Damage Done by an AI System

When an artificial intelligence system injures you, costs you money, destroys your property or data, or damages your name, someone is legally responsible for it. We identify who that is and pursue them under New York law.

Attorney Albert Goodwin
Albert Goodwin, Esq.

Artificial intelligence now drives cars, reads medical scans, screens job applicants, answers customers, moves money, and, in its newest "agentic" form, takes actions on its own inside business systems. When one of these systems gets it wrong, the harm is real: a crash, a missed diagnosis, a wiped database, a drained account, a false accusation published to anyone who asks. What is not always obvious is who answers for it. The AI itself cannot be sued. The companies that built it, sold it, deployed it, and relied on it can.

Our New York law firm represents people and businesses harmed by AI systems. These cases sit where product liability, negligence, contract, consumer protection, and defamation law meet, and much of the law is being written right now. This page explains how New York law applies, who can be held liable, and what to do to protect a claim.

How AI Systems Cause Damage

"AI damage" is not one kind of case. The type of harm determines which legal claims are available, which deadlines apply, and what compensation can be recovered. The situations we see fall into a few groups:

  • Physical injury and death: driver-assistance and self-driving systems that fail to brake or steer, warehouse and industrial robots, delivery robots and drones, AI-controlled medical devices, and diagnostic or triage software that misses a condition or recommends the wrong treatment
  • Harm from chatbots and AI companions: dangerous medical, dosing, or safety instructions, and conversational products that encourage self-harm or exploit minors and vulnerable users
  • Financial loss: AI agents that execute unauthorized purchases, transfers, or trades; automated systems that wrongly freeze accounts, deny insurance claims, or flag legitimate transactions as fraud; pricing and underwriting algorithms that act on bad data
  • Destroyed property and data: autonomous coding or operations agents that delete production databases, overwrite records, or take down systems; smart-building and industrial controls that damage equipment or premises
  • Reputational harm: generative AI that invents crimes, lawsuits, or misconduct and attributes them to a real person or business; deepfake images, audio, and video
  • Wrongful decisions about people: biased hiring and tenant-screening tools, and facial recognition misidentifications that lead to false arrest
  • False statements by a company's AI: customer-service bots that misstate prices, policies, coverage, or refund rights that the customer then relies on

Who Can Be Held Liable?

An AI system is not a legal person. Liability attaches to the humans and companies in the chain behind it, and most cases involve more than one of them:

  • The model developer: the company that trained and released the underlying AI model
  • The product company: the business that built an app, device, vehicle, or service on top of that model and put it in front of users
  • The deploying business: the hospital, employer, landlord, bank, insurer, retailer, or platform that chose to use the AI and let it make or drive decisions
  • Hardware and vehicle manufacturers: makers of the car, robot, device, or sensor the AI controls
  • Integrators and consultants: firms that configured the system, connected it to live data and permissions, and set (or failed to set) its guardrails
  • Professionals who relied on it: a physician, engineer, or other licensed professional remains responsible for their own judgment and cannot hand their duty of care to software
  • Individual bad actors: the person who used an AI tool to create a deepfake or commit a fraud

A recurring defense is "the AI did it, not us." Courts and tribunals have not been receptive. A business that puts an AI system in front of the public is generally treated as responsible for what that system says and does on its behalf, the same as it would be for an employee or any other tool it chose to use. In the widely cited Moffatt v. Air Canada decision (British Columbia Civil Resolution Tribunal, 2024), the airline argued its website chatbot was responsible for its own words; the tribunal rejected that and held the airline liable for the chatbot's misstatement. It is not New York precedent, but it reflects how ordinary agency and negligence principles are being applied.

Legal Claims Under New York Law

There is no single "AI liability" statute in New York. These cases are built from established causes of action, usually several pleaded together.

  • Strict Products Liability

    Manufacturers and sellers are strictly liable in New York for injuries caused by a defective product, whether the defect is in manufacturing, in design, or in a failure to warn. Design defect claims are judged under the risk-utility test of Voss v. Black & Decker Manufacturing Co., 59 N.Y.2d 102 (1983): did the product's risks outweigh its utility, and was a safer alternative design feasible? For AI, that inquiry looks at missing guardrails, absent human-override or confirmation steps, inadequate testing, and known failure modes left unaddressed.

    Where AI is embedded in a physical product such as a vehicle, robot, or medical device, product liability law applies in the usual way. Whether standalone software or an AI service counts as a "product" is less settled, and defendants contest it. The trend, though, is toward letting these claims proceed. In Garcia v. Character Technologies, Inc. (M.D. Fla. 2025), a federal court allowed product liability claims over an AI chatbot app to go forward, and the court overseeing the federal social media addiction litigation has analyzed specific software features as potentially defective products rather than dismissing such claims wholesale. We plead product liability alongside negligence so a case does not rise or fall on that one question.

  • Negligence

    Developers and deployers owe a duty of reasonable care. Breaches include releasing a system without adequate testing, ignoring reports of dangerous behavior, giving an AI agent sweeping permissions with no confirmation step or rollback, using a tool outside the purpose it was validated for, and failing to keep a human in the loop where the stakes demanded one. A business that deploys AI can be negligent in how it selected, configured, and supervised the system even if the underlying model was built by someone else.

  • Professional and Medical Malpractice

    When a missed diagnosis or treatment error involves AI, the physician and hospital are judged by the standard of care, and "the software said so" is not a defense. The AI vendor may be separately liable as a product manufacturer. See our medical malpractice and defective medical device pages for how those claims work.

  • Breach of Contract and Warranty

    For businesses, the strongest claim against an AI vendor is often contractual: the service agreement, the statement of work, performance and security commitments, and express warranties about what the system would and would not do. Where goods are involved, UCC Article 2 adds implied warranties of merchantability and fitness for a particular purpose. This route matters because of New York's economic loss rule, discussed below.

  • Deceptive Practices and False Advertising

    General Business Law §§ 349 and 350 prohibit deceptive acts and false advertising directed at consumers in New York, and allow recovery of actual damages and attorney's fees. Overstating what an AI product can safely do, such as marketing driver assistance as self-driving, or an AI tool as accurate, unbiased, or "human-reviewed" when it is not, can support these claims.

  • Negligent Misrepresentation

    When a company's AI gives a customer false information and the customer reasonably relies on it to their cost, the company may be liable for the misstatement. New York requires a special or privity-like relationship for this claim, so the facts of the relationship between the customer and the business matter.

  • Defamation

    A false statement of fact about an identifiable person, published to a third party, is actionable whether a human or a language model composed it. These claims face real obstacles, including fault standards and disclaimers that AI output may be inaccurate; in Walters v. OpenAI (Georgia, 2025), the court ruled for the AI company on those grounds. Outcomes depend heavily on the facts, particularly whether the company was put on notice and kept publishing the falsehood. Deepfakes may also violate New York's right-of-publicity and unlawful-dissemination statutes. More on our defamation page.

  • Discrimination by Automated Decision Tools

    The New York State and City Human Rights Laws apply to decisions made by algorithm just as they do to decisions made by people. New York City's Local Law 144 additionally requires employers using automated employment decision tools to obtain an independent bias audit and give candidates notice. In Mobley v. Workday, Inc. (N.D. Cal.), a federal court has allowed claims to proceed against the AI screening vendor itself, not only the employers who used it.

The Economic Loss Rule: Why the Type of Damage Matters

New York generally does not allow tort recovery, in negligence or strict products liability, for purely economic loss caused by a product that fails to perform. If an AI system cost your business money but injured no one and damaged no other property, the claim ordinarily has to run through contract and warranty, which means the vendor agreement and its limitation-of-liability clauses become the battlefield.

Where there is personal injury, or damage to property other than the AI product itself, tort claims are fully available, and contractual disclaimers carry far less weight. Sorting a case into the right category at the start determines which defendants, claims, and damages are realistically in play.

Defenses AI Companies Raise

These defendants are well funded and litigate hard. Expect:

  • Terms of service: mandatory arbitration, class-action waivers, liability caps, and "output may be inaccurate, verify before relying" disclaimers. Their enforceability depends on how the terms were presented and accepted, and they generally do not bind injured third parties who never agreed to them
  • "Software is not a product": an argument aimed at strict liability claims, addressed above
  • Section 230: the federal statute (47 U.S.C. § 230) shields platforms from liability for content created by others. Whether it reaches text or images an AI system generates itself is unresolved, and there is a strong argument that it does not, because the company's own system authored the content
  • The First Amendment: raised against chatbot claims in particular; the Garcia court declined to dismiss on that basis at the pleading stage
  • User misuse and comparative fault: that the user ignored warnings, misused the tool, or failed to supervise it. Under CPLR § 1411, New York's pure comparative negligence rule reduces a recovery by the plaintiff's share of fault but does not bar it
  • Finger-pointing: the developer blames the deployer's configuration, and the deployer blames the model. Naming every party in the chain prevents an empty chair at trial
  • Unforeseeability: that AI behavior is inherently unpredictable. A company that knows its system is unpredictable and releases it without safeguards has described its own negligence
  • Federal preemption: chiefly for FDA-approved medical devices

Proving the Case: Evidence Disappears Quickly

AI cases have an evidence problem ordinary cases do not. Models are updated continuously, so the version that harmed you may be gone in weeks, and the same prompt may never produce the same output twice. Logs are kept only for limited retention periods. Early action is what makes these cases provable.

  • Preservation Demands

    We send litigation-hold letters to the developer and the deploying business at the outset, demanding preservation of prompts, outputs, system instructions, model and version identifiers, agent action logs, permission settings, vehicle or device telemetry, and incident reports. Once a party is on notice, destroying that material exposes it to spoliation sanctions.

  • Technical Experts

    We work with machine learning engineers, software forensic examiners, accident reconstructionists, and human-factors experts to establish what the system did, why, and what a reasonably safe design or deployment would have looked like.

  • Internal Records

    Discovery reaches pre-release safety testing and red-team results, internal bug and incident reports, prior user complaints, decisions to ship over safety objections, and the gap between marketing claims and what engineers knew.

  • Regulatory Records

    NHTSA crash reports for driver-assistance systems, FDA adverse event reports for AI-enabled devices, and bias audits required under Local Law 144 frequently document earlier failures of the same kind.

What to Do If an AI System Harmed You

  1. Get medical care first if anyone was hurt, and follow through on treatment
  2. Capture the record now: screenshots and exports of the full conversation or session, with dates, the product name, and the version or model shown. Do not delete the chat, the account, or the app
  3. Do not try to reproduce the failure over and over, or "fix" it, in ways that overwrite logs or alter the system's state
  4. Preserve the hardware: the vehicle, device, or robot, unrepaired and unreset, including any onboard data
  5. For business losses, secure server and audit logs, take backups or snapshots, note who granted the AI its permissions and when, and collect the contract, order forms, and the vendor's marketing materials
  6. Document the damage: medical bills, lost income, lost revenue, recovery and remediation costs, and for reputational harm, who saw the false statement and what followed
  7. Report through official channels in writing and keep copies, but do not accept credits, refunds, or sign any release before getting legal advice
  8. Speak with an attorney promptly. Some deadlines in these cases are as short as 90 days or one year

Damages You Can Recover

  • Medical expenses, past and future
  • Lost wages and lost earning capacity
  • Pain and suffering and loss of enjoyment of life
  • Property damage, including the cost to restore or recreate destroyed data and systems
  • Business losses: direct losses, remediation costs, and, where provable with reasonable certainty and not barred by contract, lost profits
  • Reputational and emotional harm in defamation and deepfake cases
  • Back pay and other relief in discrimination cases
  • Statutory damages and attorney's fees under GBL §§ 349 and 350 and the Human Rights Laws, where they apply
  • Punitive damages where a company knew of a serious danger and concealed or ignored it
  • Wrongful death damages for surviving family members under EPTL Article 5

Filing Deadlines in New York

The deadline depends on the claim, and AI cases often involve several at once:

  • Personal injury and property damage (negligence, strict liability): three years, CPLR § 214
  • Defamation: one year from publication, CPLR § 215(3)
  • Medical malpractice: two years and six months, CPLR § 214-a
  • Wrongful death: two years from the date of death, EPTL § 5-4.1
  • Breach of warranty on a sale of goods: four years, UCC § 2-725
  • Breach of contract: six years, CPLR § 213(2), though many vendor contracts shorten this
  • GBL §§ 349 and 350: three years
  • Claims against the City, the MTA, or another public entity (for example, a facial recognition misidentification): a notice of claim within 90 days

Terms of service may also impose short contractual notice or claim periods. For more detail, see our page on the New York personal injury statute of limitations.

Common Questions

  • Can I sue the AI itself?

    No. An AI system has no legal personhood and no assets. You sue the companies and people responsible for building, selling, and deploying it.

  • A chatbot gave me wrong information. Do I have a case?

    It depends on the harm and on who was speaking. A general-purpose chatbot that was simply wrong, where you lost little, is usually not a viable lawsuit given the disclaimers involved. A company's own customer-facing AI that misstated its prices, policies, or coverage, or an AI product that gave dangerous instructions leading to injury, is a different matter.

  • I clicked "I agree" to terms with an arbitration clause. Is that the end of it?

    Not necessarily. Whether those terms are enforceable depends on how they were presented, and they typically do not bind people who never agreed to them, such as a pedestrian hit by a vehicle or a person defamed by an AI they never used. Where arbitration does apply, the claim can still be pursued in that forum.

  • The AI was only assisting a human. Who is responsible?

    Often both. The human or business that relied on the AI answers for their own lack of care, and the company behind the AI answers for a defective or negligently designed system. New York apportions fault among all responsible parties.

How We Handle These Cases

AI liability is a developing area, and we say so plainly: some questions in these cases have not yet been answered by New York's appellate courts. What we bring is a firm grounding in the product liability, negligence, contract, and defamation law these cases are built on, the discipline to lock down technical evidence before it disappears, and working relationships with the experts needed to explain a complex system to a judge and jury.

Injury and wrongful death cases are handled on a contingency fee, meaning no attorney's fee unless we recover compensation for you. For commercial-loss matters, you will have a clear fee structure before any engagement begins.

Related Practice Areas

Albert Goodwin gave interviews to and appeared on the following media outlets:

ProPublica Forbes ABC CNBC CBS NBC News Discovery Wall Street Journal NPR

Contact a New York Attorney for Damage Done by an AI System

If an AI system has injured you or a family member, caused your business serious loss, destroyed your data, or published falsehoods about you, do not wait. Logs are purged, models are replaced, and some filing deadlines are measured in months. Contact our office for a confidential consultation. We will assess who is responsible, which claims are available under New York law, and whether the case is worth bringing.

You can contact us by phone at 212-233-1233 or by email at [email protected].

New York State Bar Association Member Badge New York City Bar Association Member Badge American Bar Association Member Badge Avvo Rated Attorney Badge