Abstract
Legal responses to failures of generative artificial intelligence have focused primarily on the professionals who use AI-generated material. Lawyers have been sanctioned for fabricated authorities, firms have faced malpractice exposure, and courts have emphasized duties of competence, candour, and verification. Far less attention has been paid to the independent liability of the companies that design, market, integrate, and sell professional legal AI.
This article examines the potential producer liability of legal AI manufacturers under the common-law systems of the United States, Canada, and England. Drawing upon product liability, negligence, misrepresentation, failure-to-warn principles, contractual defences, and selected emerging disputes, it rejects the assumption that professional responsibility automatically displaces manufacturer responsibility. Liability may be cumulative: the professional may breach a duty to verify while the producer simultaneously breaches duties arising from superior technical knowledge, product representations, commercial benefit, and architectural control. General disclaimers cannot necessarily neutralize foreseeable or inherent defects affecting a product’s intended professional use.
The article applies the published Instrumentum Vocale doctrine to legal AI. An LLM is neither a legal actor nor an epistemic agent, but a speaking instrument operating within a human and corporate chain of responsibility. The article therefore proposes an external architecture based on assertion classification, an epistemic seam between generation and verification, qualified human review, source-level validation, provenance, and reconstructible audit trails. The decisive issue is not whether the AI can be blamed, but whether those who manufactured and controlled the instrument may escape responsibility by attributing its failures exclusively to downstream users.
Keywords: legal AI; producer liability; product liability; professional negligence; duty to warn; artificial intelligence disclaimers; generative AI; fabricated authorities; instrumentum vocale; epistemic verification; architecture of responsibility; audit trails
The use of the generative models ChatGPT (OpenAI), Gemini (Google), Grok (xAI) in drafting this article illustrates, rather than undermines, its central thesis: LLMs function as instrumenta vocalia—tools assisting in linguistic production without possessing understanding, intention, or authorship. Their involvement does not alter the locus of legal or intellectual responsibility, which remains exclusively with the human author, who makes all substantive, structural, and evaluative decisions. LLM outputs cannot be accorded independent legal or intellectual status apart from the human author.
CHAPTER 1. FROM EPISTEMIC RISK TO THE PROFESSIONAL
RESPONSIBILITY OF AI SYSTEM PRODUCERS
The contemporary debate on generative artificial intelligence is dominated by a familiar vocabulary: hallucination, bias, opacity, explainability, alignment, safety, reliability, and systemic risk. These concepts are important, but they do not fully reach the central legal and institutional problem. A probabilistic system may become more accurate, more disciplined, and more useful while remaining incapable of understanding, judgment, intention, or responsibility. The fundamental question is therefore not merely whether an AI system produces errors. It is who designed, released, represented, monitored, and commercially distributed an instrument capable of producing persuasive but potentially unreliable output at unprecedented scale.
Generative AI systems do not appear spontaneously. Their capabilities, limitations, interfaces, warnings, anthropomorphic characteristics, verification mechanisms, default settings, and permitted fields of application are the results of human and corporate decisions. The absence of artificial voluntas does not create a vacuum of responsibility. On the contrary, it directs legal attention toward the persons and institutions whose will is embedded in the architecture, deployment, and commercial presentation of the system.
The present inquiry represents the next stage in the development of the Instrumentum Vocale doctrine. Its foundational ontological proposition was formulated in Artificial Intelligence Is Slave of the Lamp: an AI system cannot become a legal subject merely because it communicates in human language or performs functions previously associated with human intelligence. It remains an object of law - an instrumentum vocale whose operation reflects the purposes, design decisions, and authority of human actors.1
That proposition was developed more systematically in LLM Is Not Artificial Intelligence, which distinguished linguistic performance from cognition, statistical generation from judgment, and operational capability from legal or epistemic agency. A large language model does not acquire voluntas, intention, understanding, or responsibility through scale, fluency, or technical complexity. The simulation of a legally significant capacity does not create the capacity itself. Nomen sine voluntate simulacrum est: a name without will is a simulacrum.2
The legal consequences of this category distinction were subsequently examined in Simulated Reasoning and the Crisis of Legal Liability. That article introduced simulated reasoning as the production of reasoning-like linguistic structures without a reasoning subject and demonstrated why classical responsibility cannot be attributed to the system generating them. If no judgment occurs within the model, responsibility must remain with the human and institutional actors who design the process, adopt the output, and act upon it.3
Later work examined the downstream side of this responsibility architecture. Procedural Liability in the Age of the LLMs addressed the non-delegable duties of lawyers and other participants in legal proceedings, while Ford v. Quill: A Turning Point in the Architecture of Modern Legal Practice examined the transformation of professional legal work and the continuing responsibility of the lawyer for reading, verification, attribution, and final judgment. An LLM may assist drafting, organization, retrieval, comparison, or preliminary synthesis, but it does not become an author, expert, verifier, officer of the court, or bearer of professional duty. Its output remains simulacrum fructus: a linguistically plausible artifact that acquires legal significance only after it has been selected, verified, adopted, and used by a human actor.4
Nippon Life v. OpenAI revealed the other side of the same architecture. Unlike cases concerned primarily with lawyers who submitted fabricated AI-generated authorities, Nippon Life directed its allegations against the provider of the generative system itself. Whatever the ultimate procedural fate of those claims, the case exposes a question that cannot be answered exclusively through the professional duties of downstream users: what responsibility belongs to the entity that designed, marketed, controlled, and distributed the instrument?5
The movement from epistemic risk to responsibility architecture therefore requires recognition of two connected but distinct loci of human control. The immediate dominus is the person or institution that selects, verifies, and acts upon a particular output. The architectural dominus is the producer that defines the system's operational boundaries, constructs its interface, represents its capabilities, controls information about its limitations, and introduces it into professional and public environments. These positions generate different duties, but neither can disappear behind the simulated agency of the model.
The user's duty to verify does not extinguish the producer's duty to design, test, disclose, warn, monitor, and correct. Conversely, defects in the producer's architecture do not automatically relieve a professional user of the obligation to exercise independent judgment. These duties are cumulative because the relevant actors control different stages of the same epistemic and operational chain.
The earlier transition from isolated model error to a broader architecture of responsibility was developed in From Epistemic Risk to Responsibility Architecture. That analysis treated hallucination, persuasion, cognitive offloading, and epistemic dependence not as isolated technical imperfections but as risks to the institutional conditions under which human beings verify claims, exercise judgment, and accept responsibility. The present article extends that analysis upstream. It asks not only who must verify an AI-generated output, but who bears responsibility for constructing and commercially distributing a system that predictably invites reliance upon such output.6
This is the missing link between the ontology of the instrument and the law of institutional responsibility. If the model possesses no will, judgment, or professional duty, responsibility cannot remain suspended inside the machine. It must be attributed to the human actors on both sides of the interface: those who use the instrument and those who create the conditions of its use.
1.1. The Producer as an Independent Locus of Responsibility
Earlier stages of the doctrine concentrated primarily on the responsibility of those who use generative systems in professional and institutional settings. Lawyers, judges, notaries, physicians, academics, public officials, and other professional actors cannot transfer their judgment or responsibility to a probabilistic language model. That conclusion remains essential, but it addresses only one part of the responsibility architecture.
The professional user is not the sole human actor in the chain. Behind the user stands another locus of control: the entity that designed the system, selected its objectives, trained and aligned it, determined its permitted functions, constructed its interface, chose its warnings, represented its capabilities, and released it into professional and public environments. The present article therefore moves the analysis upstream - from the professional responsibility of the user to the professional responsibility of the producer.
For the purposes of this article, the term AI system producer is used functionally. It includes developers, model providers, system vendors, commercial integrators, and other entities exercising material control over the design, testing, representation, distribution, monitoring, or modification of a generative AI system. The term does not assume that every such entity is already classified as a member of a licensed profession under existing law. It identifies the actor that possesses specialized knowledge unavailable to ordinary users and that controls the technical and informational conditions under which the system enters the market.
This distinction is necessary because responsibility is distributed across different levels of control. The user controls the immediate decision to rely upon and act upon a particular output. The producer controls the architecture that generates the output, the safeguards surrounding it, the claims made about its capabilities, the forms of reliance that the product encourages, and the information available to users about its limitations. These forms of responsibility are cumulative rather than mutually exclusive.
The legal problem cannot therefore be resolved by a single attribution formula under which every harmful output is assigned either to the model, the user, or the producer. The model itself possesses neither legal will nor an independent capacity to answer for consequences. Responsibility must instead be allocated among human and institutional actors according to their respective knowledge, control, representations, and capacity to prevent harm.
1.2. Product Liability and Professional Responsibility
This requires a further distinction between product liability and professional responsibility. Product liability traditionally asks whether a product was defectively designed, manufactured, or accompanied by inadequate warnings. Professional responsibility asks a broader question: whether an actor possessing specialized knowledge and occupying a position of institutional trust complied with the standards of competence, candour, care, verification, and supervision appropriate to that position.
AI system producers increasingly occupy precisely such a position. They do not merely sell passive software. They construct systems marketed as capable of reasoning, researching, advising, summarizing, coding, diagnosing, predicting, or assisting professional judgment. They control technical information that users cannot independently obtain. They conduct internal evaluations that users cannot reproduce. They determine which limitations are disclosed, which risks are minimized in marketing materials, and which safeguards remain technically possible but commercially inconvenient.
Their systems may subsequently influence legal submissions, medical decisions, financial assessments, education, public administration, engineering, scientific research, and access to essential services. The effects are therefore not confined to the contractual relationship between provider and subscriber. A person harmed by an AI-assisted decision may have had no opportunity to choose the system, read its warnings, negotiate its terms, or discover that it was used.
The resulting asymmetry is structural. The producer possesses superior knowledge of the system, while the user encounters only its interface and output. The producer controls the architecture, while the affected individual may not even know that an AI system was involved. The producer may distribute one design choice across millions of interactions, while the resulting harms appear as isolated downstream incidents. What looks like an individual user error may therefore be the visible manifestation of an upstream architectural decision.
Professional responsibility in this context does not depend exclusively upon whether the producer formally calls itself a professional. Legal duties arise from function, control, knowledge, foreseeable reliance, and the capacity to prevent harm - not merely from corporate self-description. An entity cannot simultaneously market a system through the language of expertise, reasoning, reliability, and professional assistance while treating every harmful output as an unforeseeable misuse by an autonomous user. Nor should contractual disclaimers automatically transfer the consequences of architectural and representational choices to users who lack access to the information necessary to evaluate those choices.
1.3. The Commercial Performance of Expertise
This contradiction is especially visible in the commercial presentation of generative AI. Providers frequently encourage users to treat their systems as assistants, copilots, researchers, advisers, or reasoning engines. Such terminology is not legally neutral. It shapes the degree and character of foreseeable reliance. At the same time, terms of service and product warnings may state that outputs can be inaccurate, incomplete, misleading, or unsuitable for professional reliance. The producer thus receives the commercial benefit of simulated expertise while attempting to externalize the legal cost of its unreliability.
The central issue is not whether every inaccurate output creates liability. No professional, institution, or technical system can guarantee the absence of error. The relevant question is whether the producer exercised the level of care appropriate to the risks it created and the reliance it invited. This inquiry includes the adequacy of pre-release testing, the accuracy of capability claims, the transparency of known limitations, the design of safeguards, the monitoring of recurring failure patterns, the preservation of audit trails, the speed and adequacy of corrective measures, and the decision to permit or encourage deployment in fields where errors may cause serious legal, physical, economic, or dignitary harm.
The producer's responsibility is therefore not confined to the moment of initial release. Generative AI systems are continuously updated, realigned, connected to new tools, and introduced into new institutional settings. Their risk profile may change without any corresponding change in the user's understanding. A system previously limited to generating text may acquire access to databases, communications, financial systems, or execution tools. Increased operational capability does not create artificial authority, but it expands the producer's responsibility for the conditions under which that capability is enabled.
The scale of distribution also changes the legal significance of design. A professional user's negligence may injure a client or distort a particular proceeding. A producer's defective warning, misleading capability claim, or foreseeable architectural weakness may be reproduced across jurisdictions and professions. Scale does not create a new subject of responsibility; it magnifies the consequences of the decisions made by existing subjects.
1.4. From the Talking Tool to the Complete Chain of Attribution
The Instrumentum Vocale doctrine supplies the necessary ontological foundation. The model is neither the professional nor the manufacturer. It is the instrument. Its apparent voice does not create will; its output does not create judgment; and its inability to explain or control its own operation does not relieve the human actors who designed and deployed it. The distinction between authentic human continuity and a linguistic simulation of that continuity was developed in Digital Afterlife and the Illusion of Continuity, while the non-delegable boundary of human proof, judgment, and responsibility was further articulated in When Humanity Draws the Line.7
The concept of dominus must therefore be understood at more than one level. The immediate dominus is the person or institution that selects, verifies, and acts upon the output. The architectural dominus is the entity that defines the operational boundaries of the instrument and introduces it into the market. These positions entail different duties, but neither can disappear behind the simulated agency of the model.
Accordingly, the loss of control over an AI system cannot be presented as evidence that the system has acquired an independent will. It demonstrates a failure of design, monitoring, restriction, or institutional governance: non probat voluntatem, sed defectum imperii. The more powerful and unpredictable the instrument becomes, the stronger - not weaker - the case for identifying the human actors who had the knowledge, authority, and opportunity to control it.
The central proposition of this article is therefore that producers of generative AI systems occupy a legally significant position of specialized knowledge and architectural control. Their responsibility cannot be reduced to ordinary software disclaimers or displaced entirely onto downstream users. Where they construct, market, and maintain systems intended to influence professional or consequential human decisions, they assume corresponding duties of competence, candour, validation, warning, monitoring, correction, and accountable design.
The chapters that follow examine the doctrinal basis and practical content of those duties. They also consider whether existing tort, product-liability, consumer-protection, professional-regulation, and corporate-accountability frameworks are sufficient, or whether AI system producers require a distinct and more coherent standard of professional responsibility.
Although the proposed framework may also be relevant to medical, engineering, financial, auditing, and other specialized AI systems, this article focuses on Legal AI. Legal practice provides an especially revealing case because it combines regulated professional responsibility, duties to courts and clients, reliance on authoritative sources, documented incidents of fabricated citations and verification failures, and an emerging market of systems expressly designed or represented for legal work. References to other specialized AI systems are therefore comparative and illustrative rather than the subject of comprehensive analysis. This article develops a standard for Legal AI producers, not a comprehensive theory of liability for every specialized AI system.
Instrumentum vocale has no responsibility of its own. But it has a manufacturer, a deployer, and a dominus. Liability must follow control across the entire chain.
CHAPTER 2. SCOPE AND METHOD: PRODUCER LIABILITY IN COMMON-LAW SYSTEMS
This article examines the liability of Legal AI producers within common-law systems. It does not attempt to provide a comprehensive account of civil liability under continental legal codes, nor does it offer a general survey of public-law regulation of artificial intelligence. The analysis draws principally upon the law of the United States, Canada, and England. Authorities from other common-law jurisdictions are used only where they illuminate a materially similar doctrinal problem.
These legal systems share foundational concepts of duty, reasonable care, product defect, warning, misrepresentation, reliance, causation, remoteness, and contractual allocation of risk. They nevertheless differ significantly in their treatment of strict product liability, pure economic loss, privity, disclaimers, and the boundary between products, services, software, and information. Common law is therefore treated here not as a uniform transnational code, but as a related family of doctrinal approaches.
The purpose of the comparison is functional. It identifies the legal routes through which responsibility may attach to an entity that designs, markets, distributes, monitors, and commercially maintains an AI system intended for professional legal use. Regulatory instruments may inform the content of reasonable care, but they do not replace the private-law inquiry. The central questions remain those traditionally addressed by the common law: who created the relevant risk, who possessed the knowledge and capacity to reduce it, what representations invited reliance, and which human or corporate actor exercised control at the point where the harm could have been prevented?
2.1. Doctrinal Foundations and Principal Authorities
The modern law of manufacturer liability was not built around artificial intelligence. Its classical authorities concerned automobiles, beverages, industrial machinery, pharmaceuticals, buildings, and other tangible objects. Yet the doctrinal principles developed in those settings cannot be dismissed merely because the contemporary instrument is digital, continuously updated, or capable of producing language.
The leading common-law treatments of tort and product liability identify several recurring grounds for imposing responsibility upon commercial producers. The producer designs or selects the product’s material characteristics; possesses information unavailable to ordinary users; determines how the product will be tested, described, warned about, and distributed; derives commercial benefit from its use; and is ordinarily better positioned to prevent, insure against, or distribute the cost of foreseeable harm. These considerations appear throughout the classical literature represented by Prosser and Keeton, David Owen, Mark Geistfeld, Jane Stapleton, and the American Restatements of Torts.8
The Restatement (Second) of Torts crystallized strict product liability in § 402A. The Restatement (Third) subsequently distinguished manufacturing defects, defective design, and inadequate instructions or warnings, while separately addressing component products, post-sale warnings, and the definition of a product.9 These categories do not automatically resolve the status of Legal AI. They do, however, supply the established vocabulary through which claims concerning defective architecture, inadequate safeguards, misleading warnings, and post-deployment monitoring must initially be examined.
Contemporary AI scholarship has recognized that existing doctrines face difficulties when technologically complex systems cause harm. Lemley and Casey examine the problem of remedies for harmful conduct associated with robots, while Selbst concentrates on the standard of care applicable to human users of AI systems.10 Both inquiries identify important parts of the problem. Neither, however, eliminates the antecedent question examined here: the responsibility of the corporate actors that designed the system, selected its operational characteristics, defined its commercial identity, and created the conditions of foreseeable professional reliance.
The present analysis therefore does not begin by treating the AI model as a new defendant, a quasi-person, or an autonomous bearer of obligations. Nor does it assume that the professional user is the only legally relevant human actor. The model remains an instrumentum vocale. The common-law inquiry must proceed through the existing legal subjects situated around it: producers, integrators, vendors, professional firms, individual users, and institutions. Responsibility attaches not to simulated agency, but to legally cognizable knowledge, representation, benefit, conduct, and control.
2.2. From the Manufacturer’s Duty to the Digital Producer’s Duty
The historical movement of manufacturer liability was, in substantial part, a movement away from formal distance and toward practical control. In MacPherson v. Buick Motor Co., Judge Benjamin Cardozo rejected the proposition that the absence of contractual privity necessarily insulated a manufacturer from a foreseeable user injured by a negligently inspected product.11 The wheel that failed had been manufactured by another entity, but Buick had incorporated it into the automobile and placed the completed product into commerce. The relevant question was not confined to who physically produced the defective component. It included who assembled, inspected, and released the instrument in circumstances creating a foreseeable risk of harm.
The same movement is visible in Donoghue v. Stevenson. Lord Atkin’s neighbour principle expressed the duty of reasonable care through foreseeable effects upon persons sufficiently and directly affected by the defendant’s conduct.12 Although the famous bottle of ginger beer bears little physical resemblance to a generative model, the underlying problem is recognisable: commercial manufacture and distribution can create duties extending beyond the immediate contractual counterparty.
American product-liability doctrine subsequently moved further. Justice Roger Traynor’s concurrence in Escola v. Coca-Cola Bottling Co. articulated an enterprise-based justification for placing the costs of defective products upon manufacturers capable of reducing and distributing those risks.13 Greenman v. Yuba Power Products, Inc. then established that a manufacturer could be strictly liable where a product placed on the market, intended to be used without inspection for defects, caused injury through a defect.14 These developments were later reflected in § 402A of the Restatement (Second) of Torts.
This history does not establish that every AI-generated error attracts strict liability. Nor does it erase substantial differences among common-law jurisdictions. American strict product liability, Canadian negligence doctrine, and English principles of duty and assumption of responsibility cannot be collapsed into a single rule. The importance of the authorities is more fundamental: liability cannot be avoided merely by interposing dealers, contractors, technical components, or other intermediaries between the entity exercising material control and the person foreseeably exposed to risk.
Legal AI reproduces this structural problem in a more complex chain. A foundation-model provider may supply the underlying model. A vertical-AI producer may adapt it for legal research or drafting. An integrator may connect it to proprietary databases, document-management systems, or professional workflows. A law firm may purchase and deploy it. A lawyer may rely upon a particular output. A court or client may then act upon the resulting legal document. The presence of several actors complicates attribution, but it does not justify the disappearance of responsibility.
The digital producer’s duty must therefore be examined by reference to the functions actually controlled by each participant. Relevant considerations include the selection of the underlying model; domain-specific training or fine-tuning; access to authoritative sources; interface design; confidence signals; citation generation; warnings; verification mechanisms; monitoring of recurrent defects; corrective updates; and commercial representations concerning reliability or professional capability. The fact that no single entity controls the entire system supports differentiated responsibility. It does not support a vacuum.
2.3. Products, Services, Software, and Information
Before liability can be allocated, Legal AI must be located within a body of law whose inherited categories were developed for a different technological environment. A Legal AI system may be described as software, a subscription service, an information product, a research tool, a professional assistant, or an infrastructure for professional decision-making. Each description activates different doctrinal assumptions, but none alone captures the complete transaction.
In Advent Systems Ltd. v. Unisys Corp., the United States Court of Appeals for the Third Circuit held that computer software was a “good” within the Uniform Commercial Code.15 The decision emphasized software embodied in a commercially distributed medium and the advantages of applying the UCC’s rules governing warranties, disclaimers, consequential damages, and contractual remedies. Its importance must not be overstated. Classification as a good under Article 2 of the UCC does not itself establish that every form of software, SaaS platform, or AI-generated output constitutes a product for purposes of tort liability.
The boundary between information and product has produced a different line of authority. In Saloomey v. Jeppesen & Co., mass-produced aeronautical charts were treated as products for purposes of strict liability.16 The charts were not merely abstract ideas. They were standardized technical instruments designed and sold for operational reliance in a safety-critical professional activity. Aetna Casualty & Surety Co. v. Jeppesen & Co. similarly treated the graphical presentation of flight data as a potentially defective product, while also recognizing that professional-user negligence could affect the allocation of responsibility.17
By contrast, Winter v. G.P. Putnam’s Sons declined to extend strict product liability to erroneous information contained in a book identifying mushrooms.18 The court distinguished pure expression from technical instruments such as aeronautical charts and noted that negligence, misrepresentation, and related doctrines—not strict product liability—would ordinarily govern claims concerning inaccurate published information.
Legal AI occupies the unstable space between these authorities. It is not simply a book whose text remains fixed after publication. It is an interactive computational system whose architecture, training, retrieval mechanisms, interface, safeguards, and post-release updates remain under varying degrees of producer control. It does not merely transmit a pre-existing statement. It generates individualized linguistic output in response to a user’s request and may be expressly marketed for legal research, drafting, comparison, prediction, or professional assistance.
Nor is Legal AI merely conventional software in the sense considered in Advent Systems. Its commercially relevant function lies not only in the code acquired by the user, but in an ongoing service through which the provider operates, modifies, monitors, and represents the system. The producer may change the model, retrieval sources, safety mechanisms, subscription terms, and performance characteristics without delivering a new physical object to the customer.
The product/service distinction must therefore be applied functionally and claim by claim. A design-defect allegation may concern system architecture. A warning claim may concern the interface and the producer’s knowledge of recurring hallucinations. A negligent-misrepresentation claim may concern marketing statements about accuracy or legal capability. A warranty claim may arise from contractual promises. A negligence claim may concern testing, monitoring, or failure to correct known defects. Rejecting one classification does not necessarily eliminate the others.
The decisive proposition is therefore not that all Legal AI must immediately be declared a product. It is that the producer cannot obtain the commercial advantages of presenting a standardized professional instrument while insisting, whenever harm occurs, that it supplied only intangible information for which no producer-level duty can arise.
2.4. Negligent Information and Professional Reliance
Even where product-liability doctrine is unavailable, common law has long recognized that responsibility may arise from the negligent provision of information intended to guide another person’s conduct.
In Hedley Byrne & Co. Ltd. v. Heller & Partners Ltd., the House of Lords recognized that a duty of care could arise from a special relationship involving an assumption of responsibility for information and reasonable reliance upon it.19 The particular defendant escaped liability because of the disclaimer accompanying its statement, but the case established the doctrinal foundation for recovery for negligent misstatement causing economic loss.
The Supreme Court of Canada developed this principle in Queen v. Cognos Inc. The Court identified five general requirements for negligent misrepresentation: a duty of care based upon a special relationship; an untrue, inaccurate, or misleading representation; negligence in making the representation; reasonable reliance; and resulting damage.20 Of particular importance for Legal AI, the Court also held that tortious responsibility for pre-contractual misrepresentation could exist independently of the subsequent contract.
Caparo Industries plc v. Dickman placed important limits upon liability for statements. Reasonable foreseeability alone was insufficient. The purpose for which the information was prepared, the class of persons to whom it was directed, and the transaction for which reliance was contemplated were central to proximity and the scope of the duty.21 The Supreme Court of Canada applied a related scope-of-undertaking analysis in Deloitte & Touche v. Livent Inc., emphasizing that liability must correspond to the purpose of the defendant’s undertaking and the particular reliance it was intended to induce.22
These limits are not obstacles external to the present theory; they help define it. A producer of a general conversational model does not necessarily assume responsibility for every conceivable use of every generated sentence. The position changes, however, when a system is specifically designed, integrated, or marketed for legal research, legal drafting, citation generation, case analysis, or professional decision support. The intended class of users, the known purpose of the service, and the forms of reliance encouraged by the producer become substantially more specific.
The relevant representation is also broader than the literal content of a single advertisement. Product naming, interface design, demonstrations, benchmarking claims, access to legal databases, descriptions such as “legal assistant” or “research copilot,” and the presentation of citations or confidence signals may cumulatively communicate professional competence. A producer cannot necessarily neutralize that commercial performance of expertise through a general statement, buried elsewhere, that outputs may be inaccurate.
This does not render disclaimers irrelevant. Hedley Byrne itself demonstrates their potential legal significance. Their effect must nevertheless be assessed in context: their prominence, specificity, consistency with the producer’s affirmative representations, the bargaining position of the parties, the nature of the harm, and the jurisdiction’s rules governing exclusion of liability. A disclaimer may define the undertaking. It should not automatically erase the foreseeable consequences of contradictory architectural and commercial choices.
Professional-user negligence also remains relevant. A lawyer who submits an unverified fabricated authority may breach an independent duty to the client and the court. A judge who relies upon unverified AI-generated material may breach a separate and non-delegable judicial duty. Those downstream failures may affect reliance, causation, comparative fault, contribution, and damages. They do not logically establish that the upstream producer owed no duty of its own.
2.5. Pure Economic Loss and the Limits of Recovery
The economic-loss doctrine presents one of the most significant barriers to common-law claims involving Legal AI. Many foreseeable injuries will not initially involve bodily harm or physical damage to property. They may consist of sanctions, wasted legal fees, loss of a claim or defence, an adverse judgment, an unnecessary settlement, increased litigation costs, damage to professional reputation, or disruption of institutional proceedings.
In East River Steamship Corp. v. Transamerica Delaval Inc., the United States Supreme Court held, in the admiralty context, that where a defective commercial product injures only itself and causes purely economic loss, the purchaser’s remedies ordinarily lie in contract and warranty rather than tort.23 The decision reflects a broader concern that product-liability law should not displace negotiated allocation of commercial risk.
Canadian law similarly recognizes no general right to recover in negligence for every form of pure economic loss. Winnipeg Condominium Corp. No. 36 v. Bird Construction Co. nevertheless permitted recovery of the reasonable cost of repairing a dangerous defect that posed a real and substantial threat to persons or property.24 In 1688782 Ontario Inc. v. Maple Leaf Foods Inc., the Supreme Court of Canada reaffirmed that pure economic loss remains recoverable only within carefully controlled categories and only where the claimed injury falls within the scope of a legally recognized duty.25
Legal AI exposes a structural limitation in doctrines developed around physical danger. A fabricated authority may produce no defective machine, damaged building, or physical accident. It may nevertheless corrupt a judicial record, waste public resources, prejudice a client, distort professional advice, or contribute to an unlawful decision. The absence of physical damage does not make such consequences imaginary. It does, however, affect the doctrinal route through which compensation may be sought.
For that reason, producer liability for Legal AI cannot rest exclusively upon traditional strict product liability. Negligent misrepresentation, negligent performance of a service, breach of warranty, contractual responsibility, consumer-protection law, and ordinary negligence may provide alternative or concurrent routes. Each will carry its own limitations concerning duty, reliance, privity, disclaimers, remoteness, causation, and recoverable loss.
The existence of these limitations is precisely why Legal AI requires a coherent analysis rather than a slogan. “It is only software,” “it is only information,” and “the lawyer should have checked” are not complete legal conclusions. They identify issues to be examined within the applicable cause of action. The manufacturer’s duty, the integrator’s duty, and the professional user’s duty may differ in content and scope, but they must be analyzed together rather than used to make one another disappear.
The following chapter therefore addresses the threshold classification directly: whether, and for which purposes, Legal AI should be treated as a product, a service, an information system, or a form of professional decision infrastructure.
CHAPTER 3. LEGAL AI AS A PRODUCT: TAXONOMY, PERFORMANCE CLAIMS, AND FORESEEABLE RELIANCE
3.1. The Model Is Not the Product
“Legal AI” is not a single technological object. The term may refer to a general-purpose foundation model, a legally fine-tuned language model, a retrieval system connected to proprietary legal databases, a document-analysis application, a predictive model, or an agentic platform capable of performing multi-stage professional tasks. Treating these systems as interchangeable obscures both their technical differences and the location of legally relevant control.
A model is only one component of a deployed Legal AI product. The commercial system ordinarily includes the underlying model, system prompts, retrieval architecture, databases, citation controls, user interface, access permissions, monitoring mechanisms, update procedures, contractual representations, and deployment safeguards. The producer may control some or all of these layers even where the foundational model was supplied by another entity.
This distinction is essential for attribution. A foundation-model provider may control the general architecture and training of the model. A vertical Legal AI producer may select the model, connect it to legal materials, define its professional functions, design its verification mechanisms, and market the resulting system to lawyers. An integrator may then embed the system within a law firm, court, insurer, or corporate legal department. The legally relevant product is therefore not necessarily the abstract model. It is the configured system placed into professional circulation.
3.2. A Technical Taxonomy of Legal AI
Legal AI systems can be divided into six principal technical categories.
First, rule-based expert systems apply predetermined legal rules to structured inputs. Their outputs are comparatively reproducible, and the primary risks arise from erroneous rules, incomplete decision trees, outdated law, or faulty implementation.
Second, predictive and classification models identify patterns in prior cases or documents and generate probabilities, classifications, risk scores, or recommended categories. Their principal risks concern training-data selection, representativeness, bias, calibration, and the interpretation of probabilistic outputs as legal conclusions.
Third, general-purpose foundation models generate text across numerous domains without being designed exclusively for law. Their legal capabilities are incidental to a broader linguistic architecture. Such models may produce persuasive legal language without reliable access to current authority, stable reasoning, or verifiable sources.
Fourth, legally adapted models are fine-tuned, instructed, or otherwise optimized for legal tasks. Adaptation may improve terminology, formatting, task performance, and responsiveness, but it does not by itself establish legal accuracy or eliminate the failure modes of the underlying architecture.
Fifth, retrieval-augmented generation systems combine a generative model with external databases. RAG may reduce fabricated citations by grounding answers in retrieved materials, but it introduces additional failure points: retrieval of the wrong authority, omission of controlling authority, inaccurate synthesis, jurisdictional mismatch, and citations that exist but do not support the proposition for which they are offered.
Sixth, hybrid and agentic systems combine models, retrieval engines, software tools, workflow instructions, and execution capabilities. Such systems may search databases, review documents, prepare drafts, compare authorities, populate forms, or initiate downstream actions. Their increased operational capacity also enlarges the producer’s design responsibility because an error may be propagated through several automated stages before reaching the professional user.
These categories are not mutually exclusive. A single commercial platform may combine a general-purpose foundation model, legal fine-tuning, proprietary retrieval, deterministic validation rules, and agentic workflow components. Classification must therefore follow the particular function and alleged defect rather than the product’s marketing label.
Collaborative benchmarks such as LegalBench may test models across multiple legal-reasoning tasks, but performance on such a benchmark should not be conflated with the performance of a configured commercial product deployed within a particular professional workflow.26
3.3. Classification by Professional Function
Technical architecture alone does not determine the nature of the risk. Legal AI must also be classified according to the professional function it is intended to perform.
The principal functional categories are:
legal research and authority retrieval;
citation identification and validation;
drafting and summarization;
contract analysis and redlining;
discovery, document review, and information extraction;
litigation, regulatory, or transactional risk prediction;
professional decision support; and
agentic execution of multi-stage legal workflows.
The same model may present different risks when used for different functions. A summarization error may omit a relevant contractual qualification. A research error may conceal controlling precedent. A citation error may place fabricated authority before a court. A predictive error may distort a settlement, sentencing, underwriting, or compliance decision. An agentic error may be repeated across an entire workflow before a human reviewer becomes aware of it.
Legal classification must consequently be function-specific. A system marketed merely as a linguistic drafting assistant may resemble an information service. A system sold to lawyers as an authoritative research platform, citation validator, contract reviewer, or professional decision-support infrastructure performs a materially different commercial function. The more specifically a system is designed, priced, and promoted for professional reliance, the less plausible it becomes to characterize it as the passive publication of general information.
The distinction between a software malfunction and a legally cognizable defect has also emerged in contemporary scholarship addressing product liability for AI systems.27
3.4. Performance Claims as Legally Relevant Representations
Performance claims are not external to the product. They shape the expected use of the system, the degree of foreseeable reliance, and the precautions a reasonable professional user is likely to take.
The launch of GPT-4 provides an early example. OpenAI reported that the model achieved a score of 298 on a simulated Uniform Bar Examination and placed approximately within the top ten percent of test-takers. A subsequent independent re-evaluation concluded that the percentile representation was substantially sensitive to the comparator population and methodology. Using different official datasets, the study estimated materially lower overall and written-component results.28
The example does not establish that GPT-4 was a defective legal product. It demonstrates a different point: a benchmark selected and publicized by a producer may materially influence how lawyers, clients, courts, and integrators understand the system’s professional competence. A claim about passing the bar examination is not received by the market as an abstract statement about language prediction. It is understood as evidence of legal capability.
The same problem becomes sharper where a vertical producer expressly markets a system for professional legal research. LexisNexis promoted Lexis+ AI as supplying “hallucination-free linked legal citations,” while Thomson Reuters emphasized the use of trusted Westlaw materials and safeguards intended to avoid hallucinations.29 Independent testing nevertheless found hallucinations in between 17 and 33 percent of answers produced by the tested LexisNexis and Thomson Reuters research systems.30
A linked citation may exist and still fail to support the generated proposition. A retrieved authority may be genuine but irrelevant, superseded, jurisdictionally inapplicable, or inaccurately summarized. Accordingly, “citation existence,” “citation accuracy,” “propositional support,” “completeness,” and “legal correctness” must be treated as separate performance characteristics.
These distinctions matter to product liability, negligent misrepresentation, warranty, and failure-to-warn analysis. A producer cannot market a system as professional-grade, accurate, reliable, and suitable for legal work, cultivate reliance on those representations, and then characterize the same system as a merely experimental conversational tool after harm occurs.
3.5. Independent Testing and the Problem of Comparability
Independent testing is indispensable but must itself be interpreted cautiously. There is no single measure of Legal AI performance. Bar-examination scores, hallucination rates, citation validity, document-extraction accuracy, completeness, redlining quality, latency, and professional usefulness measure different capabilities and different risks.
The 2025 Vals Legal AI Report illustrates this variability. Harvey Assistant achieved 94.8 percent on document question-and-answering, while CoCounsel achieved 77.2 percent on document summarization. Yet the lawyer baseline exceeded the participating AI systems on redlining, and the only system tested on EDGAR research scored below the lawyer baseline.31 The results therefore support neither the claim that Legal AI generally outperforms lawyers nor the opposite claim that it generally fails. They show that performance is task-dependent.
The same report also demonstrates why benchmark provenance matters. Participating producers could select the tasks in which their systems would compete and could withdraw products or results before publication. The report disclosed that LexisNexis withdrew from several categories and that the testing organization had a commercial relationship with one or more participants. It further acknowledged that its results represented a temporal snapshot of rapidly changing products.32
Consequently, every performance claim used in legal analysis should identify:
the product and version tested;
the date of testing;
the task and jurisdiction;
the dataset and comparator;
the prompting and access conditions;
the definition of accuracy or error;
whether the test was conducted or financed by the producer;
whether the data and outputs are reproducible; and
whether the tested product remains materially identical to the currently marketed system.
Appendix A records publicly available producer representations, independent performance results, public and quote-only pricing, and the limitations affecting their comparability. It does not purport to establish a permanent ranking. Its purpose is evidentiary: to identify what producers represented, what independent evaluators observed, what prices were publicly disclosed, and what limitations were publicly knowable at the relevant time.
Appendix A also places publicly disclosed Legal AI pricing alongside the transactional pricing architecture of the traditional Westlaw and LexisNexis legal databases. The comparison does not treat differently bundled subscriptions, databases, or AI services as economically identical. Rather, it provides the commercial context in which professional users assess cost, demonstrated reliability, and foreseeable reliance.
3.6. Product, Service, Software, or Information?
The technical classification of Legal AI does not automatically answer whether it constitutes a “product” for purposes of common-law products liability. Section 19 of the Restatement (Third) of Torts defines a product principally as tangible personal property distributed commercially for use or consumption.33 That formulation produces difficulty where the harmful instrument is software, an algorithm, or continuously supplied functionality.
The case law does not provide a uniform answer. In Advent Systems Ltd. v. Unisys Corp., the Third Circuit treated commercially distributed software as a good under the Uniform Commercial Code.34 By contrast, in Rodgers v. Christie, the same court concluded that an algorithmic pretrial risk-assessment instrument was not a product under the New Jersey Products Liability Act because the algorithm was neither tangible personal property nor sufficiently analogous to it.35
Cases involving informational instruments reveal a similar division. In Winter v. G.P. Putnam’s Sons, a publisher was not subjected to strict products liability for erroneous information contained in a mushroom encyclopedia.36 In Saloomey v. Jeppesen & Co., however, an aeronautical chart designed and commercially distributed for operational navigation was treated as a product.37 The distinction rested not merely upon whether information was communicated, but upon how the information was standardized, commercialized, and used within a safety-critical activity.
Legal AI occupies the boundary between these authorities. It communicates information, but it may also operate as standardized professional infrastructure. It can be updated after distribution, configured remotely, integrated into institutional workflows, and continuously controlled by its producer. A SaaS label should not determine the result where the producer retains architectural control over the system’s operation.
3.7. Locating the Alleged Defect
The appropriate classification may depend upon the location of the alleged defect.
If the complaint concerns the probabilistic behavior of the foundational model, attention may fall upon model design, training, evaluation, or known systemic limitations. If it concerns missing or inaccurate legal authority, the relevant defect may lie in database coverage, retrieval logic, jurisdictional filtering, updating, or citation validation. If the system suppresses warnings or presents uncertain output as authoritative, the defect may lie in interface design or risk communication.
Hardin v. PDX, Inc. is instructive. The claim did not merely challenge information contained in a pharmaceutical monograph. It alleged that the software producer had modified its system so that abbreviated monographs automatically omitted serious warnings.38 The legally relevant conduct therefore lay in the design and configuration of an operational information system.
The same reasoning applies to Legal AI. A hallucinated statement may originate in the model, but the actionable design choice may consist of presenting it without uncertainty markers, failing to verify citations, selecting an unsuitable underlying model, removing contrary authorities, or deploying the system for a professional task for which it was never adequately tested.
The producer need not control every component to bear responsibility for the components and representations it does control. Conversely, liability should not automatically be imposed upon the foundation-model provider for every downstream configuration created by an independent integrator. The inquiry must identify who exercised architectural control over the particular failure-producing feature.
3.8. Foreseeable Professional Reliance
A Legal AI producer may argue that professional users must independently verify every output. That obligation is real but not exclusive. The negligence of a lawyer, judge, accountant, physician, or engineer does not by itself extinguish an antecedent defect or misrepresentation by the producer.
Foreseeable verification is not equivalent to foreseeable non-reliance. Professional users purchase specialized systems precisely because those systems are represented as improving the accuracy, speed, and reliability of professional work. A producer that deliberately creates and markets such reliance cannot treat the professional user’s duty of supervision as a complete transfer of responsibility.
The classification proposed here is therefore functional and claim-specific. The same system may be treated as software for contractual purposes, as an information service for one tort claim, and as an operational product or professional decision infrastructure for another. What matters is not the producer’s preferred label, but the system’s function, method of distribution, representations, retained control, foreseeable use, and the location of the alleged defect.
Legal AI has no liability of its own. But the absence of liability in the instrument does not create an empty space around it. It directs legal analysis toward the human and corporate actors who designed, configured, marketed, deployed, and controlled the system.
CHAPTER 4. EARLY DISPUTES AND THE DEFENCES OF LEGAL AI PRODUCERS
4.1. Early Disputes and the Missing Producer
Reported litigation involving Legal AI has so far concentrated primarily upon the conduct of lawyers who relied upon defective or inaccurate outputs. Courts have sanctioned professional users, struck filings, revoked admissions, and referred lawyers for disciplinary proceedings. They have rarely asked the logically anterior question: who designed, configured, tested, and released the professional instrument that produced the defective material?
Wadsworth v. Walmart Inc. exposes this attribution gap. Attorneys representing the plaintiffs filed motions containing nine cited cases, eight of which did not exist. The cases had been generated after an attorney uploaded a draft to MX2.law, described by the court as an in-house database launched by Morgan & Morgan, and instructed it to add relevant Wyoming federal authority. The attorney who used the system received a $3,000 sanction and lost his pro hac vice admission; the supervising and local attorneys were each fined $1,000 for signing the filings without verification.39
The sanctions incident should not be treated as the firm’s first exposure to adjudicated questions of professional responsibility. Morgan & Morgan entities have previously faced malpractice judgments and awards, although those matters involved other attorneys and cannot be attributed personally to T. Michael Morgan.40
The court correctly emphasized that the lawyer’s Rule 11 obligation was non-delegable. Yet the proceeding addressed only the responsibility of the professional users. It did not examine whether MX2.law had been adequately designed or tested for legal research, whether its citation-generation function contained appropriate verification controls, or whether the system should have been capable of inserting unverified authorities directly into a professional filing.
Morgan & Morgan subsequently added an acknowledgment requiring users independently to verify AI-generated information. That remedial measure may reduce future misuse, but it also illustrates the distinction between a warning added after failure and a safeguard incorporated into the original design.
A similar pattern appeared in Gonzalez v. Texas Taxpayers and Research Association. Counsel initially denied using AI but later admitted relying upon a LexisNexis AI citation generator. The resulting brief included nonexistent authorities, incorrect citations, and real cases misrepresented as supporting unrelated propositions. The court struck the response and ordered counsel to pay $3,961.04 in fees and costs.41 Once again, the user was sanctioned, while the legal research system and its producer were not parties to the proceeding.
These decisions establish the continuing responsibility of lawyers to verify their work. They do not establish that responsibility belongs exclusively to the lawyer. A professional user’s breach may coexist with a producer’s defective design, inadequate warning, negligent representation, or breach of warranty. The liability of the last human actor should not be treated as proof that no antecedent wrong occurred elsewhere in the production chain.
The disputes involving DoNotPay moved closer to the producer itself. In MillerKing, LLC v. DoNotPay, Inc., a law firm alleged that DoNotPay falsely presented its subscription service as a “robot lawyer” capable of performing legal work without being licensed to practise law. The court dismissed the action because the plaintiff had not adequately alleged a concrete competitive injury sufficient for Article III standing. It did not adjudicate the truth of DoNotPay’s performance claims.42
In Faridian v. DoNotPay, Inc., a subscriber alleged that the service produced substandard and unusable legal documents and that he would not have purchased the subscription had he known the product was not capable of providing the represented legal assistance. The proposed class action was later settled without a reported determination of producer liability.43
Regulatory enforcement supplied the missing direct focus. The Federal Trade Commission alleged that DoNotPay promoted its service as capable of operating like a human lawyer without testing whether its legal features could do so. According to the complaint, the system had not been trained on a comprehensive and current corpus of applicable law, most of its legal outputs had not been tested for quality and accuracy, and the company had not employed or retained lawyers to conduct such testing. The final order required monetary relief, notice to former subscribers, and an end to unsupported claims that the service could substitute for professional expertise.44
These proceedings do not yet constitute a settled law of Legal AI producer liability. They nevertheless identify its emerging structure. Wadsworth and Gonzalez show the downstream consequences of defective legal output. The DoNotPay proceedings show that advertising, testing, professional validation, and product capability may become direct objects of private and public enforcement.
4.2. “It Is Only Software”: Classification as a Defence
The first defence will ordinarily be classificatory. The producer will argue that the system is not a product but software, a subscription, an information service, an interface, or merely a means of accessing a third-party foundation model. It may add that the system does not provide legal advice and that every output is supplied for informational purposes only.
As demonstrated in Chapter 3, such labels cannot resolve the legal issue. The relevant inquiry concerns the function performed, the manner of commercialization, the representations made, the control retained, and the location of the alleged defect. A system promoted as an authoritative legal research platform, citation validator, contract reviewer, or professional decision-support infrastructure performs a different commercial function from a general publication or passive repository of information.
The producer cannot reasonably present the system as professional Legal AI at the point of sale and as “only software” after harm occurs. Nor should the incorporation of a general-purpose foundation model erase the separate choices made by the vertical producer concerning retrieval, databases, system prompts, validation, interface design, warnings, and deployment.
Classification may determine which cause of action is available. It should not determine whether any responsibility exists. If strict products liability is unavailable because a court treats the system as a service or information product, negligent design, negligent performance of services, negligent misrepresentation, breach of warranty, contract, and consumer-protection law may remain available. The classification defence may redirect the action; it should not automatically terminate it.
4.3. Disclaimers, Fine Print, and Contractual Limitations
Legal AI contracts commonly disclaim warranties, exclude consequential damages, limit aggregate liability to fees paid, require individual arbitration, prohibit class proceedings, and state that outputs must be independently verified. Such terms may have substantial effect, particularly in negotiated commercial transactions between sophisticated parties. They do not create universal immunity.
Under the Uniform Commercial Code, implied warranties may be excluded by sufficiently conspicuous language, and contractual remedies and consequential damages may be limited in appropriate circumstances. But a purported disclaimer is inoperative to the extent that it cannot reasonably be reconciled with an express warranty. A limited remedy may also fail where it does not perform its essential purpose, while some exclusions remain subject to unconscionability review.45
The distinction between contractual warranty and tort liability is equally important. Section 402A, comment m, of the Restatement (Second) of Torts states that a consumer’s strict-liability claim does not depend upon contractual privity and is not defeated merely by a disclaimer accompanying the product. Courts have recognized qualifications in negotiated commercial transactions, but the general principle remains that a contractual warranty disclaimer does not automatically abolish an independent tort duty.46
The same reasoning applies to marketing representations. A producer should not be permitted to advertise a system as accurate, authoritative, professional-grade, or “hallucination-free” in prominent commercial materials and then withdraw those representations through generic language buried in contractual terms. The legal effect of the disclaimer must be assessed together with the producer’s express claims, the reasonable expectations those claims created, and the use for which the system was sold.
Nor will contractual restrictions necessarily bind injured clients, opposing parties, courts, or public authorities that never agreed to them. A contract may allocate risk between producer and purchaser. It cannot by itself determine the rights of every person foreseeably affected by the system’s professional deployment.
4.4. Inherent and Unavoidable Defects
A producer may contend that hallucination, probabilistic variation, incomplete retrieval, or occasional inaccurate synthesis are unavoidable characteristics of generative architecture rather than legally cognizable defects. This defence requires careful treatment.
Not every incorrect output proves that a product is defective. The relevant defect may instead lie in selecting an unsuitable model, connecting it to an incomplete legal corpus, failing to validate citations, suppressing uncertainty, omitting jurisdictional controls, or presenting probabilistic output through an interface that encourages professional reliance. A known architectural limitation may therefore become a design or warning defect when the system is deployed for a function incompatible with that limitation.
The traditional doctrine concerning “unavoidably unsafe products” does not establish that an unavoidable risk creates immunity. Restatement § 402A, comment k, conditions its limited protection upon proper preparation, proper marketing, and adequate directions and warnings. Courts applying the doctrine have also examined whether the risk was genuinely unavoidable and whether a feasible alternative design could have accomplished the same purpose with less danger.47
The analogy does not determine whether Legal AI is a product or whether comment k directly applies to software. It demonstrates a more general principle: unavoidability must be proved, and it does not excuse inadequate preparation, marketing, or warning.
If a risk cannot be eliminated, responsibility shifts toward controlling, disclosing, and limiting the uses exposed to that risk. A producer may need to restrict the system’s functions, require external verification, prevent unsupported citations from being exported, preserve source provenance, disclose known error rates, or refrain from marketing the product for tasks it cannot reliably perform.
A warning is not adequate merely because it mentions that mistakes are possible. It must communicate the nature, frequency, seriousness, and practical consequences of the relevant risk. A statement that “AI may make mistakes” may be insufficient where the producer knows that the system can fabricate authorities, omit controlling precedent, or generate genuine citations that do not support the propositions stated.
The central proposition is therefore straightforward:
Unavoidability is not immunity. A producer cannot invoke the inherent limitations of probabilistic architecture as a defence after marketing those same limitations out of the commercial description of the product.
4.5. “The Professional Should Have Checked”
The most powerful defence will be that the lawyer or other professional user had an independent duty to verify every output. That duty is real. It is also not exclusive.
A lawyer who files invented authority may be sanctioned even if the false citation originated in a commercial Legal AI system. A law firm may be liable to its client for failing to supervise the use of the system. Depending upon the jurisdiction and the facts, such conduct may constitute contributory or comparative negligence, misuse, assumption of risk, or an intervening cause.
But foreseeable verification is not equivalent to foreseeable non-reliance. Producers sell specialized Legal AI precisely because it is represented as making professional work faster, more accurate, and more reliable. A system that required the user independently to reconstruct every stage of its research would surrender much of the commercial utility for which it is purchased.
The manufacturer’s defence must therefore depend upon the particular failure. Did the user ignore a clear and adequate warning? Did the user employ the product for a prohibited purpose? Did the producer supply reliable source links and verification controls that the user deliberately bypassed? Or did the system present fabricated or unsupported material as verified authority within the very workflow for which it was designed and sold?
The professional user’s negligence may reduce recovery or support contribution between responsible parties. It does not retroactively cure a defective design, make a misleading representation true, or eliminate the producer’s prior failure to warn.
4.6. Economic Loss and the Fragmentation of Responsibility
Where the alleged harm consists solely of lost fees, an adverse judgment, settlement costs, wasted professional time, or other financial loss, the producer may invoke the economic-loss doctrine. As discussed in Chapter 2, the doctrine may restrict negligence or strict-liability claims and direct commercially disappointed purchasers toward contract and warranty remedies. Its scope, exceptions, and treatment of negligent misrepresentation differ across common-law jurisdictions.48
The doctrine is significant, but it is not a universal answer. Claims involving physical injury, damage to other property, independent misrepresentations, statutory consumer protection, professional services, express warranties, restitution, contribution, or indemnity may follow different routes. The absence of one cause of action does not establish the absence of every remedy.
Finally, each participant in the Legal AI chain may attempt to externalize responsibility. The foundation-model provider may blame the vertical producer. The vertical producer may blame the underlying model. The integrator may blame the law firm. The firm may blame the individual lawyer. The lawyer may blame the interface, the database, or the producer’s advertising.
The complexity of the supply chain may complicate the allocation of liability, but it cannot be permitted to dissolve liability altogether. The proper inquiry is not which actor controlled the entire system. It is which actor controlled the particular design, representation, warning, database, deployment decision, or professional act that contributed to the harm.
Neither contractual labels nor mountains of paperwork can erase responsibility for a defect originating within a product that was designed, configured, marketed, and placed into professional circulation. The producer may not be the only responsible actor. But where the defect originated in the producer-controlled system, the existence of downstream responsibility does not make the producer disappear.
This conclusion leads directly to the instrumentum vocale doctrine. The instrument has no will and bears no liability of its own. Responsibility must therefore be attributed to the human and corporate actors according to their control over its design, representations, deployment, verification, and final use.
CHAPTER 5. INSTRUMENTUM VOCALE: FROM PRODUCT LIABILITY TO AN ARCHITECTURE OF RESPONSIBILITY
The disputes examined above reveal a deeper problem. The central question is not whether lawyers, judges, or other professionals remain responsible when they use artificial intelligence. They do. The harder question is whether that responsibility can be used to conceal the independent responsibility of those who design, market, and sell defective AI systems.
It cannot.
An LLM is neither a lawyer nor an expert, witness, judge, or epistemic agent. It is an instrumentum vocale: a speaking instrument capable of producing persuasive linguistic artifacts without possessing knowledge, judgment, professional duty, or responsibility for their consequences. Its fluency does not transform probabilistic synthesis into legal reasoning. Its confidence does not establish accuracy. Its ability to reproduce the form of authority does not make it an authority.
The doctrinal and architectural foundation for this approach was developed in our earlier joint work, Instrumentum Vocale and the Architecture of Responsibility: From Liability to Embedded Accountability.49 That doctrine treats the generative model as an instrumentum vocale operating within an external architecture of verification, attribution, auditability, and non-delegable human responsibility. The present analysis applies that framework specifically to legal AI and to the allocation of responsibility among professional users, deploying institutions, and product manufacturers.
This distinction is not merely philosophical. It determines the proper architecture of liability.
The professional who submits an AI-assisted document remains responsible for reading it, verifying it, and adopting it as his or her own work. A signature, however, cannot retrospectively cure a defective product. Nor does the negligence of a lawyer necessarily extinguish the responsibility of a manufacturer that knowingly supplied a system prone to fabricated authorities, false quotations, corrupted citations, invented procedural histories, or simulated verification.
Responsibility is not a single object that must be assigned either to the user or to the manufacturer. Different actors may be responsible for different failures within the same causal chain. The lawyer may fail to verify. The firm may fail to supervise. The court may fail to impose adequate safeguards. The developer may fail to test, constrain, warn, monitor, or correct a foreseeable defect. The legal AI vendor may market reliability that its product cannot deliver. One failure does not erase another.
This is why disclaimers cannot perform the work of engineering.
A contractual statement that “AI may make mistakes” may warn of residual risk. It cannot immunize a manufacturer against an inherent, foreseeable, and insufficiently controlled defect at the core of the product’s intended legal use. A vendor cannot advertise a system as a professional legal assistant, integrate it into research and drafting workflows, encourage reliance upon its outputs, and then retreat behind fine print declaring that nothing produced by the system should be trusted.
Where the defect is structural, the response must also be structural.
The Instrumentum Vocale doctrine therefore requires an external architecture of control and verification built around the generative model. The model itself is interchangeable. The durable legal object is the architecture governing what may enter the professional workflow, what must be verified, who may verify it, how verification is documented, and who assumes responsibility before the output affects another person’s rights.
At minimum, that architecture must contain four elements.
First, the system must classify the nature and sensitivity of its assertions—the cardo argumenti. A quotation, citation, holding, procedural fact, statutory provision, legal inference, strategic recommendation, and rhetorical formulation cannot be treated as epistemically equivalent. Each requires a different level and method of scrutiny.
Second, every material assertion must cross an epistemic seam: a boundary between generated language and verified information. Verification must occur against identifiable external authorities and source documents. Another LLM repeating, approving, or reformulating the same proposition is not independent verification. Internal consistency multiplies correlation, not truth.
Third, verification must be performed or certified by a qualified human professional. The verifier must possess both substantive competence in the relevant field and sufficient training to understand the characteristic failure modes of generative systems. A human button press is not judgment: digitus non est iudicium. If the professional has not read the authority, examined the source, and evaluated the proposition, there has been no meaningful verification. Verificatio sine lectione est simulatio verificationis.
Fourth, the process must create a contemporaneous provenance and audit trail. It must be possible to reconstruct what the system generated, which sources were consulted, what was changed, who verified each material proposition, and who authorized the final use. A polished interface, a green checkmark, or an automatically generated “verified” label is not proof. Simulacrum probationis non est probatio.
Legal AI makes this architecture especially urgent because legal language acts upon institutions. A fabricated citation does not remain a private computational error. Once incorporated into a pleading, opinion, expert report, settlement analysis, or legal advice, it enters a system of rights, duties, sanctions, property, liberty, and public authority. The defect crosses the epistemic seam and becomes an institutional event.
The manufacturer of legal AI must therefore design for the foreseeable environment in which the product will be used. This includes source-level traceability, reliable access to underlying authorities, jurisdictional and temporal validation, detection of quotation and citation mismatch, clear separation between generated analysis and retrieved legal material, preservation of the verification record, and effective controls against representations of verification that never occurred.
These safeguards do not prohibit legal AI. They establish the conditions under which it may be used without dissolving responsibility. Nor do they convert the manufacturer into the lawyer or the lawyer into a software engineer. They preserve the distinct obligations of each actor.
The professional remains the gatekeeper of the legal act. The manufacturer remains responsible for the safety and integrity of the instrument placed in that professional’s hands. Neither may disappear behind the other.
The alternative is an architecture of abdication: the developer points to the user, the user points to the system, the institution points to its policy, and the machine—incapable of duty, fault, or punishment—is presented as the final cause. That is not accountability. It is the systematic disappearance of the dominus from the chain of responsibility: abdicatio officii domini.
When an AI system produces false authority or escapes effective control, this does not prove that the instrument has acquired judgment or will. It proves that human governance has failed: non probat voluntatem, sed defectum imperii.
The coming litigation against legal AI manufacturers will therefore not be resolved by anthropomorphic debates about whether the machine “thought,” “decided,” or “hallucinated.” Courts will ask more conventional and more dangerous questions: Was the defect foreseeable? Was the product marketed for the use that produced the harm? Were reasonable safeguards technically available? Did the manufacturer adequately test and monitor the system? Could the risk have been reduced without destroying the product’s utility? And can a disclaimer lawfully transfer the consequences of an inherent defect to the person injured by it?
The future of legal AI will be determined not by the eloquence of the model, but by the architecture surrounding it. The model may change tomorrow. The obligations to verify, attribute, document, and answer for its use will remain. An artificial voice cannot bear legal responsibility; the human beings and corporations that design it, sell it, deploy it, certify it, and act through it can.
APPENDIX A
PUBLICLY REPORTED PERFORMANCE AND PRICING OF LEGAL AI SYSTEMS:
PRODUCER REPRESENTATIONS AND INDEPENDENT EVALUATIONS
Scope note. This Appendix is not a permanent product ranking. It records task-specific, version-specific, and time-specific public evidence relevant to foreseeable reliance, product representations, warning duties, and the producer's knowledge of system limitations. Pricing entries distinguish producer-published figures from quote-only sales processes; unverified market estimates are excluded. Different benchmarks and differently bundled prices are not directly interchangeable.
| SYSTEM AND TYPE | PRODUCER REPRESENTATIONS AND PUBLIC PRICING | INDEPENDENT EVIDENCE AND LIMITATIONS |
|---|---|---|
GPT-4 OpenAI General-purpose foundation model; legally relevant benchmark use |
Reported result: 298/400 on a simulated Uniform Bar Examination; described as approximately the 90th percentile or the top 10% of test-takers. [A1] Scope: The claim concerned a simulated examination, not a dedicated legal-research product or a measure of day-to-day lawyer performance. Public price: Current general-purpose ChatGPT plans list Plus at USD 20/month, Pro at USD 200/month, and Business at USD 20/user/month when billed annually (USD 25 monthly). These are not prices for the retired GPT-4 configuration tested above; API use is separately billed. [A10]-[A11] |
Independent re-evaluation: Using a recent July comparator, below the 69th percentile overall and about the 48th percentile on essays. Estimated against first-time takers: about the 62nd percentile overall and 42nd on essays; against those who passed: about the 48th percentile overall and 15th on essays. [A2] Legal-research test: 21% accurate, 21% incomplete, and 58% hallucinated across a preregistered set of more than 200 legal queries. [A4] Limitation: Bar-exam performance and open-ended legal-research reliability measure different capabilities. |
Lexis+ AI LexisNexis RAG-based proprietary legal-research system |
Representation: "100% Hallucination-Free Linked Legal Citations" connected to source documents; the producer separately stated that the promise was not one of complete answer accuracy. [A3] Pricing transparency: Quote-only. The current Lexis+ with Protege product page offers a demo but states no public list price. The price therefore cannot be compared without a jurisdiction-, content-, seat-, and contract-specific quotation. [A12] |
Stanford/Yale evaluation: 65% accurate, 18% incomplete, and 17% hallucinated. [A4] Statutory-survey benchmark (2026): 64% accuracy on multi-jurisdictional statutory research. [A9] Limitation: The studies tested dated product versions and different legal tasks. A real citation may still fail to support the proposition for which it is offered. |
Westlaw AI-Assisted Research Thomson Reuters RAG-based proprietary legal-research system |
Representation: The producer stated that it "avoid[s]" hallucinations by relying on trusted Westlaw content and checks and balances intended to ground answers in good law. [A5] Pricing transparency: Partial. Online pricing is limited to new U.S. firms with up to ten attorneys; larger firms and existing customers must contact sales. A current public in-house package, CoCounsel Legal, starts at USD 1,694.90/month and includes Westlaw Advantage plus other products; it is not a standalone price for the tested AI-Assisted Research tool. [A13]-[A14] |
Stanford/Yale evaluation: 42% accurate, 25% incomplete, and 33% hallucinated. [A4] Statutory-survey benchmark (2026): 58% accuracy on multi-jurisdictional statutory research. [A9] Limitation: The 2024 and 2026 studies examined different tasks and versions; neither result should be projected automatically onto the current product. |
Ask Practical Law AI Thomson Reuters RAG system grounded in Practical Law resources |
Representation: The producer stated that "all the responses are based on the expert resources of Practical Law." [A4] Related public package price: Practical Law Dynamic Tool Set with CoCounsel Essentials currently starts at USD 882.30/month for the public in-house offering. No separate public price is stated for Ask Practical Law AI itself. [A13] |
Stanford/Yale evaluation: 22% accurate, 62% incomplete, and 17% hallucinated (percentages rounded in the published figure). [A4] Limitation: The dominant failure mode was incompleteness rather than fabrication; the two risks should not be collapsed into a single accuracy measure. |
Harvey Assistant Harvey Multi-model vertical Legal AI assistant |
Producer benchmark: Harvey reported a 0.2% hallucination rate - approximately one hallucinated claim per 500 claims - on a subset of BigLaw Bench tasks. [A6] Metric: Sentences containing a demonstrably false factual claim divided by total response sentences; the definition excluded reasoning, relevance, and usefulness errors. Pricing transparency: Quote-only. Harvey states that pricing is customized by team size, deployment scope, and product surfaces and is disclosed during evaluation; no public rate card is provided. [A15] |
Vals Legal AI Report: 75.1% data extraction; 94.8% document Q&A; 72.1% summarization; 65.0% redlining; 77.8% transcript analysis; and 80.2% chronology generation. [A7] Limitations: Vendors selected participating tasks and could withdraw results; Harvey withdrew from EDGAR Research. Vals disclosed a customer relationship with one or more participants. [A7] |
CoCounsel 2.0 Thomson Reuters / Casetext Vertical Legal AI assistant and document-analysis system |
Representation: Casetext stated that CoCounsel "does not make up facts, or hallucinate" because controls limit it to known reliable sources or require it not to answer. [A4] Public starting prices: For the current in-house offering, CoCounsel Legal starts at USD 1,694.90/month and CoCounsel Essentials at USD 340.85/month. These are starting package prices, not normalized per-seat figures; firms with more than ten attorneys are directed to sales. [A13]-[A14] |
Vals Legal AI Report: 73.2% data extraction; 89.6% document Q&A; 77.2% summarization; and 78.0% chronology generation. [A7] Complex extraction example: 61.7% of 40 requested fields extracted accurately across three credit agreements, the best result among tested systems on that example. [A7] Limitation: CoCounsel participated in four of seven reported task categories; these scores do not test every advertised workflow. |
Vincent AI vLex (part of Clio) Multi-model RAG and agentic Legal AI platform |
Current public claims: At least 38% productivity improvement across legal workflows and 3.67 times greater reliability than leading LLMs in cited independent benchmarking studies. [A8] Architecture claim: Responses are grounded in vLex legal materials and supplied with links permitting professional verification. [A8] Pricing transparency: Quote-only. The current Vincent page offers a personalized demo and free trial but displays no public list price; subscription scope varies by region, content, and organizational deployment. [A16] |
Vals Legal AI Report: 69.2% data extraction; 72.7% document Q&A; 58.9% summarization; 53.6% redlining; and 64.8% transcript analysis. [A7] Limitation: vLex withdrew from chronology generation. Current marketing claims may concern later versions and studies not identical to the February 2025 Vals test. |
Oliver Vecflow (now August) Multi-model and agentic legal-workflow platform |
Public-data status: No directly comparable producer-issued numerical accuracy or hallucination claim was identified in the reviewed open materials. Pricing transparency: Quote-only. The current August site invites prospects to request a demo and a free live workflow, but states no list price. August identifies Vecflow as its former company name. [A17]-[A18] |
Vals Legal AI Report: 64.0% data extraction; 74.0% document Q&A; 62.4% summarization; 66.9% chronology generation; and 55.2% EDGAR Research. [A7] Limitation: Oliver was the only product reported in the EDGAR Research category, preventing a direct product-to-product comparison for that task. |
HEAD-TO-HEAD: LEXISNEXIS AND WESTLAW
The comparison below places public price architecture beside independently reported performance. It does not equate a transactional charge with a subscription price or treat differently bundled products as economically identical.
| MEASURE | LEXIS+ WITH PROTEGE | WESTLAW AI-ASSISTED RESEARCH / RELATED PACKAGE |
|---|---|---|
| PUBLIC SUBSCRIPTION PRICE | Customized quotation only; the producer states that price varies by organization size, capabilities, and content scope. [A12] | Partial disclosure. The related CoCounsel Legal package, which includes Westlaw Advantage and other products, starts at USD 1,694.90/month for the public in-house offering; no standalone public rate is stated for the tested AI-Assisted Research tool. [A13]-[A14] |
| OFF-SUBSCRIPTION TRANSACTIONAL LIST PRICE | The 2026 Large Legal schedule lists General AI at USD 12; General AI with LexisNexis content and Generative AI Ask at USD 99; and Generative AI Summarize or Drafting at USD 250 per chargeable activity. These prices apply outside flat-rate subscription scope and exclude discounts. [A19] | The published Westlaw Schedule A lists transactional searches from USD 0 to USD 310 and a State Survey find at USD 250. The schedule does not identify those figures as a standalone price for AI-Assisted Research. [A20] |
| INDEPENDENT LEGAL-RESEARCH TEST | 65% accurate; 18% incomplete; 17% hallucinated. [A4] | 42% accurate; 25% incomplete; 33% hallucinated. [A4] |
| 2026 MULTI-JURISDICTIONAL STATUTORY SURVEY | 64% accuracy. [A9] | 58% accuracy. [A9] |
Transparency finding. Independent performance can be compared directly because both products were tested under the same published protocol. Their subscription prices cannot: LexisNexis uses individualized quotations, while Thomson Reuters publishes selected bundle starting prices but not a standalone AI-Assisted Research rate. The market therefore permits a public performance comparison while withholding a normalized price-performance comparison.
Interpretive caution. A lower hallucination rate does not necessarily imply greater completeness, legal correctness, or professional usefulness. Likewise, a strong score on document Q&A cannot be treated as evidence of equivalent performance in open-ended legal research, redlining, or agentic execution. Absence of a public list price is not evidence that a price is excessive; it is evidence that an external observer cannot test the price-performance relationship without access to an individualized quotation and contract terms.
SOURCES
[A1] OpenAI, GPT-4 Technical Report, arXiv:2303.08774 (2023), pp. 5-6, https://cdn.openai.com/papers/gpt-4.pdf.
[A2] Eric Martinez, Re-evaluating GPT-4's Bar Exam Performance, 33 Artificial Intelligence and Law 581-604 (2025), https://doi.org/10.1007/s10506-024-09396-9.
[A3] LexisNexis, How Lexis+ AI Delivers Hallucination-Free Linked Legal Citations (May 3, 2024), https://www.lexisnexis.com/community/insights/legal/b/product-features/posts/how-lexis-ai-delivers-hallucination-free-linked-legal-citations.
[A4] Varun Magesh et al., Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools, arXiv:2405.20362 (2024), esp. figs. 1-2, https://arxiv.org/abs/2405.20362.
[A5] Thomson Reuters, Breaking New Ground: Utilizing AI-Assisted Research on Westlaw Edge Canada with CoCounsel (June 18, 2024), https://legal.thomsonreuters.com/blog/breaking-new-ground-utilizing-ai-assisted-research-on-westlaw-edge-canada-with-cocounsel/.
[A6] Harvey Team, BigLaw Bench: Hallucinations (Oct. 7, 2024), https://www.harvey.ai/blog/biglaw-bench-hallucinations.
[A7] Vals AI & Legaltech Hub, Vals Legal AI Report (Feb. 27, 2025), https://www.vals.ai/industry-reports/vlair-2-27-25.
[A8] vLex, Vincent: AI Engineered for Lawyers, product and methodology statements, https://ca.vlex.com/vincent-ai.
[A9] Mohamed Afane, Emaan Hariri, Derek Ouyang & Daniel E. Ho, Benchmarking Legal RAG: The Promise and Limits of AI Statutory Surveys, arXiv:2603.03300 (2026), https://arxiv.org/abs/2603.03300.
[A10] OpenAI, ChatGPT Pricing, https://openai.com/chatgpt/pricing/.
[A11] OpenAI, Business Pricing, https://openai.com/business/pricing/.
[A12] LexisNexis Canada, Lexis+ with Protege: Legal AI for Drafting, Research, and Analysis, https://www.lexisnexis.com/en-ca/products/lexis-plus-protege.
[A13] Thomson Reuters, Compare CoCounsel Plans for Your Legal Team, including publicly displayed starting prices, https://legal.thomsonreuters.com/en/c/compare-cocounsel-plans-for-your-legal-team.
[A14] Thomson Reuters, CoCounsel Legal Plans and Pricing; online-pricing eligibility and sales-routing terms, https://legal.thomsonreuters.com/en/products/cocounsel-legal/plans.
[A15] Harvey, Top Harvey AI Use Cases for Law Firms and In-House Teams, pricing FAQ, https://www.harvey.ai/blog/top-harvey-use-cases.
[A16] vLex, Vincent: AI Engineered for Lawyers, demo and trial page, https://ca.vlex.com/vincent-ai.
[A17] August, Legal AI Workspace for Law Firms, https://www.august.law/.
[A18] Thomas Bueler-Faudree, What We Built in 2025, August (2026), identifying Vecflow as the former company name, https://www.august.law/us/blog/what-we-built-in-2025.
[A19] LexisNexis, Large Legal Price Schedule (effective Jan. 5, 2026), transactional list prices outside flat-rate subscription scope, https://www.lexisnexis.com/en-us/terms/SALargeLegal/pricing.page.
[A20] Thomson Reuters, Schedule A to Subscriber Agreement, transactional Westlaw charges, https://store.legal.thomsonreuters.com/law-products/_ui/common/webResources/ScheduleA.pdf.
All online sources last accessed 1 September 2026. Prices are in U.S. dollars and may change; taxes, implementation, integrations, usage limits, discounts, minimum commitments, and negotiated terms may be additional unless expressly included by the producer.
References
Kildeev, A., Artificial Intelligence Is Slave of the Lamp, Scientific Platform XXI Century, Issue 6 (September 2025); DOI: 10.2139/ssrn.5843202, accessed on 29.08.26.
Kildeev, A., LLM Is Not Artificial Intelligence; Scientific Platform XXI Century, Issue 7 (October 2025); DOI: 10.2139/ssrn.5754202, accessed on 29.08.26.
Kildeev, A., Simulated Reasoning and the Crisis of Legal Liability (April 4, 2026); DOI: 10.2139/ssrn.6524139.
Kildeev, A., Procedural Liability in the Age of the LLMs (2026), SSRN Working Paper No. 6648340, DOI: 10.2139/ssrn.6648340.
Kildeev, A., Ford v. Quill: A Turning Point in the Architecture of Modern Legal Practice (August 5, 2026), DOI: 10.5281/zenodo.22165830.
Kildeev, A., Nippon Life v. OpenAI: Tort, Unauthorized Practice of Law and the First Private Offensive Against LLM-Assisted Legal Drafting (March 11, 2026); DOI: 10.2139/ssrn.6395278.
Kildeev, A., From Epistemic Risk to Responsibility Architecture: AI, Human Judgment, and the Instrumentum Vocale Doctrine (June 28, 2026), DOI: 10.5281/zenodo.22165647.
Kildeev, A., Digital Afterlife and the Illusion of Continuity: Legal and Ethical Aspects of Post-Mortem Digital Simulation (2026), Scientific Platform XXI Century, Issue 3 (March 2026); SSRN Working Paper No. 6241379, DOI: 10.2139/ssrn.6241379.
Kildeev, A., When Humanity Draws the Line: LLMs, Proof, and Human Responsibility (2026), SSRN Working Paper No. 6895120, DOI: 10.2139/ssrn.6895120.
W. Page Keeton, Dan B. Dobbs, Robert E. Keeton, and David G. Owen, Prosser and Keeton on the Law of Torts, 5th ed. (St. Paul, MN: West Publishing Co., 1984).
David G. Owen, Products Liability Law, 3rd ed. (St. Paul, MN: West Academic Publishing, 2015).
Mark A. Geistfeld, Principles of Products Liability, 3rd ed. (St. Paul, MN: Foundation Press, 2020).
Jane Stapleton, Product Liability (London: Butterworths, 1994).
Restatement (Second) of Torts § 402A (American Law Institute, 1965); Restatement (Third) of Torts: Products Liability §§ 1–2, 5, 10, 19 (American Law Institute, 1998).
Mark A. Lemley and Bryan Casey, “Remedies for Robots,” University of Chicago Law Review 86 (2019): 1311–1396.
Andrew D. Selbst, “Negligence and AI’s Human Users,” Boston University Law Review 100 (2020): 1315–1376.
MacPherson v. Buick Motor Co., 217 N.Y. 382, 111 N.E. 1050 (1916).
Donoghue v. Stevenson [1932] A.C. 562 (H.L.).
Escola v. Coca-Cola Bottling Co. of Fresno, 24 Cal. 2d 453, 150 P.2d 436 (1944) (Traynor, J., concurring).
Greenman v. Yuba Power Products, Inc., 59 Cal. 2d 57, 377 P.2d 897 (1963).
Advent Systems Ltd. v. Unisys Corp., 925 F.2d 670 (3d Cir. 1991).
Saloomey v. Jeppesen & Co., 707 F.2d 671 (2d Cir. 1983).
Aetna Casualty & Surety Co. v. Jeppesen & Co., 642 F.2d 339 (9th Cir. 1981).
Winter v. G.P. Putnam’s Sons, 938 F.2d 1033 (9th Cir. 1991).
Hedley Byrne & Co. Ltd. v. Heller & Partners Ltd. [1964] A.C. 465 (H.L.).
Queen v. Cognos Inc., [1993] 1 S.C.R. 87.
Caparo Industries plc v. Dickman [1990] 2 A.C. 605 (H.L.).
Deloitte & Touche v. Livent Inc. (Receiver of), 2017 SCC 63, [2017] 2 S.C.R. 855.
East River Steamship Corp. v. Transamerica Delaval Inc., 476 U.S. 858 (1986).
Winnipeg Condominium Corp. No. 36 v. Bird Construction Co., [1995] 1 S.C.R. 85.
1688782 Ontario Inc. v. Maple Leaf Foods Inc., 2020 SCC 35, [2020] 3 S.C.R. 504.
Neel Guha et al., LegalBench: A Collaboratively Built Benchmark for Measuring Legal Reasoning in Large Language Models, arXiv:2308.11462 (2023).
Asaf Lubin, On Software Bugs and Legal Bugs: Product Liability in the Age of Code, 100 Indiana Law Journal 1891 (2025).
OpenAI, GPT-4 Technical Report, arXiv:2303.08774 (2023); Eric Martínez, Re-evaluating GPT-4’s Bar Exam Performance, 33 Artificial Intelligence and Law 581 (2025).
LexisNexis, How Lexis+ AI Delivers Hallucination-Free Linked Legal Citations (May 3, 2024); Thomson Reuters, Where Legal Research Meets Generative AI (Nov. 15, 2023).
Varun Magesh et al., Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools, arXiv:2405.20362 (2024).
Vals AI & Legaltech Hub, Vals Legal AI Report (Feb. 27, 2025).
Restatement (Third) of Torts: Products Liability § 19 (American Law Institute 1998).
Advent Systems Ltd. v. Unisys Corp., 925 F.2d 670, 675–76 (3d Cir. 1991).
Rodgers v. Christie, 795 F. App’x 878, 880 (3d Cir. 2020).
Winter v. G.P. Putnam’s Sons, 938 F.2d 1033, 1034–36 (9th Cir. 1991).
Saloomey v. Jeppesen & Co., 707 F.2d 671, 676–77 (2d Cir. 1983).
Hardin v. PDX, Inc., 227 Cal. App. 4th 159, 163–66, 173 Cal. Rptr. 3d 397 (2014).
Wadsworth v. Walmart Inc., 348 F.R.D. 489, 493–96, 501–05 (D. Wyo. 2025).
Gonzalez v. Texas Taxpayers and Research Association, No. 1:24-CV-880-RP, Document 29 (W.D. Tex. Jan. 29, 2025).
MillerKing, LLC v. DoNotPay, Inc., 702 F. Supp. 3d 762, 768–75 (S.D. Ill. 2023).
Class Action Complaint ¶¶ 1–7, 35, Faridian v. DoNotPay, Inc., No. CGC-23-604987 (Cal. Super. Ct. Mar. 3, 2023), subsequently removed, No. 3:23-cv-01692-RFL (N.D. Cal.); Sara Merken, Legal AI Startup DoNotPay Reaches Settlement in Customer Class Action, Reuters (June 6, 2024).
Complaint ¶¶ 5, 20–24, In re DoNotPay, Inc., FTC Matter No. 2323042 (Sept. 25, 2024); Decision and Order, FTC Matter No. 2323042 (Jan. 17, 2025).
U.C.C. §§ 2-316(1)–(2), 2-719.
Restatement (Second) of Torts § 402A cmt. m (American Law Institute 1965); Iowa Electric Light & Power Co. v. Allis-Chalmers Manufacturing Co., 360 F. Supp. 25, 31–32 (S.D. Iowa 1973).
Restatement (Second) of Torts § 402A cmt. k (American Law Institute 1965); Toner v. Lederle Laboratories, 112 Idaho 328, 336–37, 732 P.2d 297, 305–06 (1987); Taylor v. Intuitive Surgical, Inc., 187 Wash. 2d 743, 762–67, 389 P.3d 517 (2017).
See East River Steamship Corp. v. Transamerica Delaval Inc., 476 U.S. 858 (1986); Winnipeg Condominium Corp. No. 36 v. Bird Construction Co., [1995] 1 S.C.R. 85; 1688782 Ontario Inc. v. Maple Leaf Foods Inc., 2020 SCC 35, [2020] 3 S.C.R. 504.
Thorben Liebig and Adel Kildeev, Instrumentum Vocale and the Architecture of Responsibility: From Liability to Embedded Accountability, SSRN Working Paper No. 6868460 (2026), permanent open-access record: https://zenodo.org/records/22071989.
Kildeev, A., Artificial Intelligence Is Slave of the Lamp, Scientific Platform XXI Century, Issue 6 (September 2025), pp. 3-31; DOI: 10.2139/ssrn.5843202, accessed on 29.08.26.↩︎
Kildeev, A., LLM Is Not Artificial Intelligence; Scientific Platform XXI Century, Issue 7 (October 2025), pp. 3-44; DOI: 10.2139/ssrn.5754202, accessed on 29.08.26.↩︎
Kildeev, A., Simulated Reasoning and the Crisis of Legal Liability (April 4, 2026); DOI: 10.2139/ssrn.6524139.↩︎
Kildeev, A., Procedural Liability in the Age of the LLMs (2026), SSRN Working Paper No. 6648340, DOI: 10.2139/ssrn.6648340; Kildeev, A., Ford v. Quill: A Turning Point in the Architecture of Modern Legal Practice (August 5, 2026), DOI: 10.5281/zenodo.22165830.↩︎
Kildeev, A., Nippon Life v. OpenAI: Tort, Unauthorized Practice of Law and the First Private Offensive Against LLM-Assisted Legal Drafting (March 11, 2026); DOI: 10.2139/ssrn.6395278.↩︎
Kildeev, A., From Epistemic Risk to Responsibility Architecture: AI, Human Judgment, and the Instrumentum Vocale Doctrine (June 28, 2026), DOI: 10.5281/zenodo.22165647.↩︎
Kildeev, A., Digital Afterlife and the Illusion of Continuity: Legal and Ethical Aspects of Post-Mortem Digital Simulation (2026), Scientific Platform XXI Century, Issue 3 (March 2026), pp. 18-35; SSRN Working Paper No. 6241379, DOI: 10.2139/ssrn.6241379; Kildeev, A., When Humanity Draws the Line: LLMs, Proof, and Human Responsibility (2026), SSRN Working Paper No. 6895120, DOI: 10.2139/ssrn.6895120.↩︎
W. Page Keeton, Dan B. Dobbs, Robert E. Keeton, and David G. Owen, Prosser and Keeton on the Law of Torts, 5th ed. (St. Paul, MN: West Publishing Co., 1984); David G. Owen, Products Liability Law, 3rd ed. (St. Paul, MN: West Academic Publishing, 2015); Mark A. Geistfeld, Principles of Products Liability, 3rd ed. (St. Paul, MN: Foundation Press, 2020); Jane Stapleton, Product Liability (London: Butterworths, 1994).↩︎
Restatement (Second) of Torts § 402A (American Law Institute, 1965); Restatement (Third) of Torts: Products Liability §§ 1–2, 5, 10, 19 (American Law Institute, 1998).↩︎
Mark A. Lemley and Bryan Casey, “Remedies for Robots,” University of Chicago Law Review 86 (2019): 1311–1396; Andrew D. Selbst, “Negligence and AI’s Human Users,” Boston University Law Review 100 (2020): 1315–1376.↩︎
MacPherson v. Buick Motor Co., 217 N.Y. 382, 111 N.E. 1050 (1916).↩︎
Donoghue v. Stevenson [1932] A.C. 562 (H.L.).↩︎
Escola v. Coca-Cola Bottling Co. of Fresno, 24 Cal. 2d 453, 150 P.2d 436 (1944) (Traynor, J., concurring).↩︎
Greenman v. Yuba Power Products, Inc., 59 Cal. 2d 57, 377 P.2d 897 (1963).↩︎
Advent Systems Ltd. v. Unisys Corp., 925 F.2d 670 (3d Cir. 1991).↩︎
Saloomey v. Jeppesen & Co., 707 F.2d 671 (2d Cir. 1983).↩︎
Aetna Casualty & Surety Co. v. Jeppesen & Co., 642 F.2d 339 (9th Cir. 1981).↩︎
Winter v. G.P. Putnam’s Sons, 938 F.2d 1033 (9th Cir. 1991).↩︎
Hedley Byrne & Co. Ltd. v. Heller & Partners Ltd. [1964] A.C. 465 (H.L.).↩︎
Queen v. Cognos Inc., [1993] 1 S.C.R. 87.↩︎
Caparo Industries plc v. Dickman [1990] 2 A.C. 605 (H.L.).↩︎
Deloitte & Touche v. Livent Inc. (Receiver of), 2017 SCC 63, [2017] 2 S.C.R. 855.↩︎
East River Steamship Corp. v. Transamerica Delaval Inc., 476 U.S. 858 (1986).↩︎
Winnipeg Condominium Corp. No. 36 v. Bird Construction Co., [1995] 1 S.C.R. 85.↩︎
1688782 Ontario Inc. v. Maple Leaf Foods Inc., 2020 SCC 35, [2020] 3 S.C.R. 504.↩︎
Neel Guha et al., LegalBench: A Collaboratively Built Benchmark for Measuring Legal Reasoning in Large Language Models, arXiv:2308.11462 (2023).↩︎
Asaf Lubin, On Software Bugs and Legal Bugs: Product Liability in the Age of Code, 100 Indiana Law Journal 1891 (2025).↩︎
OpenAI, GPT-4 Technical Report, arXiv:2303.08774 (2023); Eric Martínez, Re-evaluating GPT-4’s Bar Exam Performance, 33 Artificial Intelligence and Law 581 (2025).↩︎
LexisNexis, How Lexis+ AI Delivers Hallucination-Free Linked Legal Citations (May 3, 2024); Thomson Reuters, Where Legal Research Meets Generative AI (Nov. 15, 2023).↩︎
Varun Magesh et al., Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools, arXiv:2405.20362 (2024).↩︎
Vals AI & Legaltech Hub, Vals Legal AI Report (Feb. 27, 2025).↩︎
Id., Methodology and Participating Vendors sections.↩︎
Restatement (Third) of Torts: Products Liability § 19 (American Law Institute 1998).↩︎
Advent Systems Ltd. v. Unisys Corp., 925 F.2d 670, 675–76 (3d Cir. 1991).↩︎
Rodgers v. Christie, 795 F. App’x 878, 880 (3d Cir. 2020).↩︎
Winter v. G.P. Putnam’s Sons, 938 F.2d 1033, 1034–36 (9th Cir. 1991).↩︎
Saloomey v. Jeppesen & Co., 707 F.2d 671, 676–77 (2d Cir. 1983).↩︎
Hardin v. PDX, Inc., 227 Cal. App. 4th 159, 163–66, 173 Cal. Rptr. 3d 397 (2014).↩︎
Wadsworth v. Walmart Inc., 348 F.R.D. 489, 493–96, 501–05 (D. Wyo. 2025).↩︎
This institutional history concerns Morgan & Morgan entities and other individual attorneys; it does not establish that T. Michael Morgan personally participated in the underlying malpractice. In Morgan & Morgan, P.A. v. Pollock, 306 So. 3d 1251, 1252–57 (Fla. 2d DCA 2020), a jury found Morgan & Morgan and one of its attorneys liable for legal malpractice and awarded $5 million. The appellate court affirmed the liability determination but directed that the $4.5 million component attributable to one group of underlying defendants be remitted to $250,000 because only that amount had been proved collectible; a separate $500,000 component was not challenged on appeal. More recently, an American Arbitration Association tribunal granted in their entirety claims for legal malpractice, breach of contract, and breach of fiduciary duty against Morgan & Morgan, PLLC, and a former firm attorney. It awarded the claimant $450,000 in compensatory damages, $250,000 for emotional distress, $413,180.33 in attorney’s fees and costs, and $3.15 million in punitive damages, plus $37,737.50 in previously incurred costs. The respondents were also ordered to bear $56,300 in AAA and arbitrator expenses. Wyrosdick v. Morgan & Morgan, PLLC & Corey Aitken, AAA Case No. 01-25-0001-6505, Award of Arbitrator (July 7, 2026). The Atlanta Journal-Constitution subsequently reported that the award had been paid; Morgan & Morgan stated that it strongly disagreed with the arbitrator’s findings. These matters are cited solely as institutional context and do not determine any issue concerning the design or operation of MX2.law.↩︎
Gonzalez v. Texas Taxpayers and Research Association, No. 1:24-CV-880-RP, Document 29 (W.D. Tex. Jan. 29, 2025).↩︎
MillerKing, LLC v. DoNotPay, Inc., 702 F. Supp. 3d 762, 768–75 (S.D. Ill. 2023).↩︎
Class Action Complaint ¶¶ 1–7, 35, Faridian v. DoNotPay, Inc., No. CGC-23-604987 (Cal. Super. Ct. Mar. 3, 2023), subsequently removed, No. 3:23-cv-01692-RFL (N.D. Cal.); Sara Merken, Legal AI Startup DoNotPay Reaches Settlement in Customer Class Action, Reuters (June 6, 2024).↩︎
Complaint ¶¶ 5, 20–24, In re DoNotPay, Inc., FTC Matter No. 2323042 (Sept. 25, 2024); Decision and Order, FTC Matter No. 2323042 (Jan. 17, 2025).↩︎
U.C.C. §§ 2-316(1)–(2), 2-719.↩︎
Restatement (Second) of Torts § 402A cmt. m (American Law Institute 1965); Iowa Electric Light & Power Co. v. Allis-Chalmers Manufacturing Co., 360 F. Supp. 25, 31–32 (S.D. Iowa 1973).↩︎
Restatement (Second) of Torts § 402A cmt. k (American Law Institute 1965); Toner v. Lederle Laboratories, 112 Idaho 328, 336–37, 732 P.2d 297, 305–06 (1987); Taylor v. Intuitive Surgical, Inc., 187 Wash. 2d 743, 762–67, 389 P.3d 517 (2017).↩︎
See East River Steamship Corp. v. Transamerica Delaval Inc., 476 U.S. 858 (1986); Winnipeg Condominium Corp. No. 36 v. Bird Construction Co., [1995] 1 S.C.R. 85; 1688782 Ontario Inc. v. Maple Leaf Foods Inc., 2020 SCC 35, [2020] 3 S.C.R. 504.↩︎
Thorben Liebig and Adel Kildeev, Instrumentum Vocale and the Architecture of Responsibility: From Liability to Embedded Accountability, SSRN Working Paper No. 6868460 (2026), permanent open-access record: https://zenodo.org/records/22071989.↩︎