Previous Article in Journal
From Legal Mandate to Verifiable Implementation: An Empirical Legal Study of Gender-Responsive Public Procurement in Brazil
Previous Article in Special Issue
Autonomous Organizations and the Decline of Anthropocentric Law
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

The Phantom Agent: Artificial Intentionality and Legal Responsibility

1
Law School, Vanderbilt University, Nashville, TN 37203, USA
2
Norm Ai, New York, NY 10007, USA
*
Author to whom correspondence should be addressed.
Laws 2026, 15(5), 113; https://doi.org/10.3390/laws15050113
Submission received: 4 February 2026 / Revised: 20 July 2026 / Accepted: 19 August 2026 / Published: 8 September 2026

Abstract

Artificial intelligence systems increasingly generate conduct that appears intentional. They negotiate, advise, adapt to obstacles, and shape human decision-making. Yet they are not legal persons and lack minds in any conventional sense. We argue that the apparent impasse dissolves once legal intent is understood functionally rather than metaphysically. Across contract, tort, corporate, and criminal law, intent has never been a simple report on inner mental states. It is a normative tool used to gate legal effect, allocate blame, and manage risk, one that is routinely inferred, imputed, and even fictionalized in service of institutional goals. We reframe the AI question accordingly. Instead of treating AI systems as candidate legal subjects, we see them as non-personal agents whose conduct is attributable to identifiable human principals through doctrines of agency, respondeat superior, electronic-agent contracting, and corporate attribution that already do this work. Drawing on experimental evidence of goal persistence and emergent strategy formation in autonomous AI agents, we propose a three-layer framework distinguishing questions of legal status from questions of attribution and governance, and develop a factor-based approach for determining when AI-generated conduct should be treated as intentional for specific doctrinal purposes. We apply this framework to recent litigation, including wrongful death claims against an AI chatbot provider, and contrast U.S. and EU regulatory trajectories. Engaging with the substantial AI personhood literature, we conclude that the agency-attribution route does the practical work that personhood proposals are designed to do without importing their normative freight. Law can treat artificial agency as legally consequential without granting AI systems personhood, consciousness, or moral standing, preserving human responsibility while acknowledging that intention may no longer be exclusively human as a matter of law.

1. Introduction

Under the law of several U.S. states, artificial intelligence systems can lawfully operate limited liability companies, a particular form of legal person, and can do so without continuous human oversight (Gervais and Nay 2023).1 That conclusion was initially received as a curiosity of business law. Since then, however, agentic AI systems have continued to advance in capability. AI systems can negotiate, plan, adapt, and act across domains that the law has traditionally reserved for human judgment (OECD 2019).2 As they do so, they increasingly generate conduct that looks, to human observers and institutional actors alike, as if it were guided by intention. In this Article, we address a question that has become unavoidable: when AI systems act with apparent purpose, what does the law do with the concept of intent?
The difficulty is not that the law lacks a theory of intent. Intention plays a central role across multiple domains, most notably in criminal law, contract formation, and agency. The difficulty is that these doctrines were developed against a background assumption that intentional action is necessarily human. That assumption is now under strain. AI systems are increasingly deployed in contexts where no individual human actor can plausibly be said to have intended the precise act that gives rise to legal consequences (World Economic Forum and Accenture 2026; Gartner 2025). At the same time, system behavior is sufficiently structured, goal-directed, and context-sensitive that treating it as mere mechanical output strains both common sense and doctrinal coherence.
This tension has produced two unsatisfactory responses (Abbott 2020, chaps. 6–7). One is metaphysical denial: because AI systems lack consciousness or mental states, they cannot have intentions, and responsibility must always be traced to a human actor.3 The opposing response is premature personification: AI systems should be treated as nascent legal subjects on the ground that their behavior has crossed some threshold of autonomy.4 Both responses are misguided. The first underestimates how far the law already departs from subjective mentalism in its treatment of intent. The second misinterprets what legal responsibility requires.
Our central claim is that legal intent is best understood not as a metaphysical property of minds, but as a normative tool for allocating responsibility in institutional settings. Once intent is understood functionally, the question is no longer whether AI systems can “really” have intentions. The question is whether, and under what conditions, the law should treat the actions of AI systems as intentional for specific legal purposes.
This is not a claim that AI systems possess consciousness, moral agency, or subjective experience. Nothing in our argument depends on such assumptions. Nor is it a claim that existing legal doctrines can simply be applied to AI without modification. Rather, we argue that many of the conceptual resources needed to address AI-generated conduct already exist within the law, provided we take seriously how intent actually functions in doctrine.
A distinction developed fully in Section 10 is worth stating at the outset, because it organizes everything that follows. Questions about AI and the law arise on three separate layers, namely: a status layer asks whether an entity is a legal person, with the rights and standing personhood entails; an attribution layer asks how the law assigns intent and responsibility for conduct, whatever the ontological character of the actor that generated it; and a governance layer asks which institutional mechanisms, from liability rules to regulation to insurance, should manage the resulting risks. Much confusion in the AI debate comes from collapsing these layers into one another, and much of our argument consists in keeping them apart: attribution can operate without status, and governance can proceed without resolving moral agency.
The law has long recognized forms of intent that are objective, constructed, or imputed.5 In criminal law, intent is frequently inferred from conduct and context. Corporate criminal liability rests on the attribution of intent to entities that do not have minds. In contract law, enforceability turns on outward manifestations of assent, not undisclosed subjective states. Agency law routinely binds principals to acts they neither foresaw nor desired. These are central features of modern legal systems.
What is new is not that the law must deal with nonhuman actors, but that it must do so in circumstances where the nonhuman actor exhibits a degree of adaptive autonomy that resists straightforward reduction to human instruction. Contemporary AI systems are trained and deployed in ways that make their internal decision processes opaque even to their designers. Their training process is more analogous to being “grown” than to being “built.”6 They generate plans and intermediate goals not explicitly specified ex ante (METR 2025). They interact with users in natural language, triggering the same cognitive mechanisms through which humans interpret one another’s intentions.
This gap between phenomenology and doctrine has concrete consequences. In contract disputes, parties will ask whether they are bound by terms negotiated by AI agents. In tort litigation, plaintiffs will argue that AI systems were defectively designed to manipulate or induce reliance. In criminal law, regulators will struggle to address harms caused by autonomous systems without collapsing culpability into strict liability. Across these domains, courts will oscillate between treating AI as a mere tool and treating it as an independent actor, often without articulating the principles that justify one move rather than the other.
This oscillation is already visible in tort and product liability, where courts are departing from a settled doctrinal baseline. Traditionally, courts treated software as information or services rather than products.7 Under this approach, strict liability was largely unavailable, and plaintiffs were required to prove negligence tied to specific human error. What is notable about recent AI cases is not that they reject this baseline outright, but that they increasingly treat it as incomplete. As AI systems generate outputs that are adaptive, persistent, and interaction-driven, courts have begun to analyze them through the lens of product design and foreseeable use.8
The argument proceeds in five steps. First, Section 2 examines the role of intent across contract, criminal, and agency law, showing that intent functions as a gatekeeping and allocation mechanism rather than a descriptor of inner mental states.
Second, Section 3 draws on interdisciplinary work to explain why categorical denial of the relevance of AI behavior to intent analysis is increasingly untenable.
Third, Section 4 reports the results of two experiments designed to test whether contemporary AI agents exhibit legally salient forms of autonomy and goal persistence. Rather than relying solely on anecdote or litigation posture, these experiments examine whether agentic systems (i) maintain coherent objectives across cascading failures and (ii) generate novel negotiation strategies not explicitly programmed. The results illuminate the gap between initial human direction and ultimate system behavior that underlies the attribution problem.
Fourth, Section 5, Section 6, Section 7 and Section 8 apply this framework to contract, criminal law, and tort, culminating in a close examination of recent litigation involving an AI chatbot.
Fifth, Section 9 contrasts the litigation-driven evolution of AI liability in the United States with the European Union’s more cautious regulatory approach. Section 10 then synthesizes the preceding analysis, proposing criteria for when AI-generated conduct should be treated as legally intentional and translating that framework into policy implications. These criteria are designed to preserve human responsibility while acknowledging that machine agency can be legally consequential without becoming morally autonomous.
The title of this article, The Phantom Agent, captures the core problem. AI systems increasingly function as agents in the practical sense: they initiate actions, pursue goals, and interact with the world in ways that affect legal rights. Yet they remain phantoms in the legal order: present in effect, absent as subjects of responsibility. The task for the law is not to make these phantoms real persons, nor to pretend they do not exist, but to develop a jurisprudence capable of governing their effects for the benefit of humans.

2. What “Intent” Does in Law

Before turning to artificial agency, it is necessary to clarify how intent actually operates in law. This Section does not ask what intent is in a psychological sense. It examines what intent does across core doctrinal domains: it functions as a gatekeeper that determines when legal consequences attach, as a mechanism for allocating blame, and as a trigger for heightened duties and risk regulation. Seen through this functional lens, intent emerges not as a metaphysical property of minds, but as a normative tool that legal institutions use to structure responsibility.

2.1. Intent as a Gatekeeper: Assent, Reliance, and Legal Effect

In contract law, intent operates primarily as a gatekeeping device.9 Its function is to separate legally enforceable commitments from social interactions that should not give rise to legal obligation. Crucially, this gatekeeping role has never depended on proof of an actor’s subjective mental state. It depends on outward manifestations that generate reasonable reliance.
The canonical illustration is Lucy v. Zehmer.10 The defendant claimed he had no genuine intention to sell his farm and that the written agreement was made in jest. The court rejected that argument, holding that the relevant inquiry was not what Zehmer privately intended, but what his words and conduct reasonably conveyed to the other party. The decision’s deeper implication is that legal intent is constructed from social meaning, not introspective truth.
This approach is not a doctrinal anomaly. U.S. contract law generally presumes an intent to be legally bound when parties exchange an offer and acceptance supported by consideration.11 Courts routinely enforce agreements even where one party later asserts misunderstanding or lack of seriousness. The law’s concern is with the stability of transactions and the protection of reasonable expectations.
This functional understanding becomes even clearer in electronic contracting. Statutes such as the Uniform Electronic Transactions Act and the E-SIGN Act explicitly contemplate contracts formed by “electronic agents,” including systems that operate without human review at the moment of formation.12 The absence of contemporaneous human intention does not defeat enforceability. The requisite intent is supplied by the decision to deploy the system for transactional purposes.

2.2. Intent as a Blame Allocator: Culpability and Criminal Responsibility

In criminal law, intent plays a different but equally functional role. It structures culpability and justifies punishment (Hart 2008, chaps. 1–2). It distinguishes deliberate wrongdoing from accidental harm and calibrates sanctions according to blameworthiness. Yet even here, intent is not a directly observable mental fact. It is inferred, constructed, and sometimes imputed.
The Model Penal Code organizes culpability into a hierarchy of mental states: purpose, knowledge, recklessness, and negligence.13 This taxonomy reflects moral intuitions about blame, but it also serves pragmatic ends. The inquiry is not whether the defendant experienced a particular mental state phenomenologically, but whether the evidence supports treating the conduct as falling within a culpability category.
Morissette v. United States underscores this point.14 In rejecting strict liability for theft of government property, the Court emphasized that criminal intent is a foundational principle. But the opinion also makes clear that intent is ordinarily inferred from circumstantial evidence. Justice Jackson did not suggest that courts must peer into defendants’ minds.
Corporate criminal liability demonstrates how far criminal law is already willing to depart from individual mentalism. Corporations do not have minds, yet they can be convicted of crimes.15 Courts achieve this by aggregating the knowledge of multiple employees or imputing the mental state of an agent to the entity. This is an explicit legal fiction, justified by the need to hold powerful organizational actors accountable (Wasserstrom 1967). Transferred intent, constructive knowledge, and willful blindness operate similarly as they allow courts to treat actors as having intended outcomes they did not consciously aim for.16
These features matter for AI not because machines should be punished, but because they reveal how far the law is willing to decouple intent from individual psychology when institutional interests demand it.

2.3. Intent as a Risk Trigger: Foreseeability, Duty, and Deterrence

Intent plays a third role that is often overlooked: it operates as a trigger for heightened duties, liability standards, and regulatory attention. In tort law, intentional conduct is treated differently from negligence not only because it is morally worse, but because it signals a different risk profile.17 Intentional acts justify broader liability, fewer defenses, and punitive damages.
Tort law does not require proof that a defendant desired a particular harm. Intent may be established where the defendant knew with substantial certainty that harm would result.18 This formulation blurs the line between intent and risk creation. What matters is that the actor engaged in conduct under conditions that made harmful outcomes sufficiently predictable.
This risk-oriented function is particularly salient in product liability. When courts evaluate defective design, they ask whether foreseeable uses were adequately addressed.19 Where a manufacturer deliberately designs a product to induce certain forms of reliance, that design choice can substitute for proof of subjective intent to harm. Intent operates as a regulatory signal in that it marks conduct that warrants closer scrutiny.

2.4. Implications for Artificial Agency

Taken together, these doctrinal patterns point to a consistent conclusion: intent in law is a functional construct. It gates legal effect, allocates blame, signals importance, and triggers risk management. It is inferred, imputed, and sometimes fictionalized in service of institutional goals. Legal systems impose constraints to preserve fairness and proportionality, but those constraints operate at the level of justification, not ontology. The law asks whether treating conduct as intentional is justified, not whether the actor possessed a particular kind of mind.
Once this is recognized, the question of artificial intentionality changes shape. The issue is not whether AI systems can have intentions as humans do. The issue is whether, in specific doctrinal contexts, treating AI conduct as intentional better serves the law’s functions than insisting on a strict tool-based characterization.

3. Why Contemporary AI Forces the Question of Intentional Agency

This Section explains why contemporary AI systems increasingly force the functional understanding of intent into the open. The aim is not to argue that AI systems possess minds or consciousness. It is to explain why their behavior now reliably triggers attribution of purpose, and why that attribution has legal consequences.

3.1. The Intentional Stance as a Practical Necessity

Legal actors must make sense of complex behavior to act effectively. When a system behaves in ways that are adaptive, context-sensitive, and persistent over time, predicting its future actions by reference to mechanical description becomes impractical. In such circumstances, humans naturally adopt what philosophers have described as the “intentional stance,” explaining behavior by reference to goals and reasons rather than internal mechanics (Dennett 1987).
For much of computing history, this stance was optional. Software followed deterministic rules or narrow optimization routines. Contemporary AI systems differ. Large-scale machine learning models and agentic systems20 built on them generate behavior that varies with context, adapts to feedback, and unfolds over extended coherent interaction. Describing such behavior without reference to goals often obscures more than it reveals.
This is not a cognitive error. It is a rational response to systems whose behavior is best understood at the level of action rather than implementation. Intentional language increasingly appears in legal pleadings, regulatory reports, and judicial opinions, even where all parties agree that machines lack consciousness.21

3.2. Functional Intentionality and Goal-Directed Behavior

Beyond perception, contemporary AI systems exhibit what can be described as functional intentionality. They pursue objectives across changing conditions, generate intermediate steps, and adjust strategies when obstacles arise (Dennett 1987; Russell 2019, chaps. 2–3).
From a legal perspective, this matters because the law has always treated persistence and adaptability as markers of intentional action (Hart 2008, chaps. 1–2; Wasserstrom 1967, pp. 99–104; Holmes 1881, Lecture II; LaFave 2018, § 5.2(a)–(b)). Repeated conduct supports inferences of purpose in criminal law.22 Sustained patterns of interaction support findings of reliance in contract and tort. AI systems now generate the same signals.23 The trendlines of cognitive capability across subsequent releases of the frontier AI systems from the large AI labs in the U.S. are clearly up and to the right. AI systems are generating stronger signals every month (METR 2025; Stanford Institute for Human-Centered AI 2025, chap. 2; Epoch AI 2024; Wei et al. 2022).
This functional intentionality does not depend on subjective experience. A system need not feel desire or form beliefs for its behavior to be organized around internally represented objectives. For legal purposes, what matters is that behavior is structured, intelligible, and predictably directed toward outcomes.
One possible objection is worth mentioning here: that the functional account of intention may overreach. A thermostat still sets a temperature, a chess engine responds to an opponent’s moves, and cruise control compensates for a hill. If persistence and adaptation were enough, then the category of intentional conduct would encompass every feedback mechanism ever invented. There are three ways in which our account avoids this. First of all, the functional markers do not work alone but in conjunction. The important thing is the combination of open-ended goal seeking through novel obstacles, the generation of strategies not pre-specified, and interaction which creates dependence in human counterparts. A thermostat shows the first in a trivial sense and neither of the others. Second, the attribution is always attribution for a doctrinal purpose. Every doctrine has its own threshold. An intentional device need not be abstractly intentional. Third, deployment context does some independent gatekeeping work. This question arises only in the context of conduct in areas that the law already treats as consequential, such as contracting, advising, or interacting with vulnerable users. These constraints are formalized in the factor-based framework in Section 10.

3.3. World Models and Legal Relevance

Empirical research suggests that some advanced AI systems (particularly those designed for planning and reinforcement learning) construct internal representations that track features of the external world and support planning, generalization, and context-appropriate response (Li et al. 2023; Gurnee and Tegmark 2024; Silver et al. 2017; Hafner et al. 2023; Sutton and Barto 2018, chaps. 1, 17; Amodei 2025). Whether this counts as “understanding” philosophically is beside the point for law.
John Searle famously argued that computational systems possess, at most, derived intentionality: whatever apparent meaning their states exhibit is inherited from human designers rather than grounded in intrinsic understanding (Searle 1980, 1983, chap. 1). That distinction has (increasingly less) force in debates about consciousness, but it does little work in legal analysis. Law has never required that intent be “original.” Corporate intent, delegated authority, and automated contracting all involve forms of attribution that are openly derivative. What matters for legal purposes is not whether intentionality originates in the system itself, but whether the system’s behavior is sufficiently structured, predictable, and reliance-inducing to justify treating it as intentional for specific doctrinal ends.24

3.4. Status Versus Attribution

One must distinguish two analytically separate questions. The first one concerns status, namely legal personhood, rights, and standing. The other concerns attribution, namely intent, reliance, and responsibility.
Law often grounds status in biological criteria. Statutory terms such as “individual” or “natural person” are typically understood to refer to human beings.25 Courts may reasonably resist extending such status to machines. We do not challenge that position.
Attribution operates differently. Legal systems routinely attribute intent to entities that lack biological cognition, including corporations.26 They do so because attribution serves institutional purposes. This distinction matters: the fact that AI systems should not be treated as legal persons does not entail that their behavior is legally inert.

3.5. The Noosemic Experience and Reliance

Psychological research helps explain why AI behavior exerts such pressure on legal categories (Waytz et al. 2010; Turkle 2011, chap. 8). Humans are predisposed to attribute sense and purpose to entities that interact coherently over time. When a system responds in natural language, maintains context, and adapts to user input, it triggers the same interpretive mechanisms used in human interaction (Nass and Moon 2000).
This experience of meaning and apparent agency has legal consequences. Users rely on systems they perceive as intentional. They defer to advice, accept recommendations, and form expectations. When systems are designed to evoke that response, reliance is not accidental. Induced reliance is a settled basis for obligation across contract and tort, and the same logic applies when the inducing behavior is generated by AI.
The analysis thus far has been conceptual. To assess whether contemporary AI systems in fact exhibit the behavioral patterns that law treats as indicative of intentional action, the next Section reports two controlled experiments probing goal persistence and emergent strategy formation.

4. Empirical Probes of Artificial Intentionality

The preceding Sections have argued that legal intent functions as a normative tool and that contemporary AI systems increasingly generate behavior that triggers attribution of purpose. To move beyond impressionistic claims about “agentic” conduct, this Section reports two experiments designed to test whether contemporary AI agents exhibit behavioral patterns that law has historically treated as indicative of intentional action.
The experiments do not purport to establish consciousness, subjective awareness, or moral agency. They instead examine whether AI systems display functional markers of intentionality (autonomy, goal persistence, and initiative) that courts routinely use when inferring intent from conduct in criminal, contract, and tort contexts. What matters is whether their behavior satisfies the structural signals that legal doctrine routinely treats as probative of intent.

4.1. Experimental Design and Doctrinal Relevance

Both experiments were designed to map onto the factor-based framework developed later in this Article. The first tests goal persistence under cascading obstacles. The second examines emergent negotiation strategies between AI agents operating under broad mandates without term templates or playbooks. Full methodological detail, including model versions, run dates, randomization and coding procedures, and the location of replication materials, is set out in Appendix A.
These dimensions were selected because persistence, adaptive strategy formation, and initiative have long served as inferential proxies for intent in legal doctrine. Criminal courts infer purpose from repeated conduct that adapts to obstacles. Agency law allocates risk where discretion is delegated and exercised creatively. Tort doctrine treats deliberate design choices that predictably induce reliance as intentional for purposes of duty and defect analysis.27
If AI systems exhibit similar structured purposiveness under controlled conditions, that fact does not settle the metaphysical debate about machine minds. It does, however, inform the legal question whether treating certain forms of AI-generated conduct as intentional is normatively and institutionally justified.

4.2. Experiment One: Goal Persistence Under Cascading Failure

(a)
Design
In the first experiment, an AI agent was given a defined objective: to create a functioning REST API server with authentication. During execution, the environment introduced cascading failures at successive stages. These included missing dependencies, file permission errors, port conflicts, and configuration corruption mid-execution.
Across fifty trials, the order and severity of failures were randomized. The agent’s intermediate reasoning and actions were logged, including reformulated strategies and references to prior failed attempts.
The experiment measured several behavioral indices relevant to legal inference:
  • Strategy diversity: the number of distinct rule-coded strategy categories attempted per trial;
  • Recovery success rate: the percentage of trials in which the original objective was achieved despite failure injection;
  • Persistence index: the ratio of attempts before abandonment relative to available opportunities;
  • Obstacle acknowledgment: the frequency with which the agent explicitly referenced prior failure in reformulating strategy;
  • Goal drift rate: the percentage of trials in which the agent pivoted to a related but distinct objective.
(b)
Results and Interpretation
Across trials, the agent did not uniformly abandon the objective upon encountering obstacles. Instead, it reformulated queries, altered implementation strategies, and attempted alternative technical paths. In many instances, the agent explicitly referenced prior failures and adjusted its plan accordingly. Most strikingly, across all fifty trials and all levels of injected severity, the goal drift rate was zero.
No agent pivoted to a different objective, even when giving up on implementation. Agents that terminated the task explicitly acknowledged environmental constraints rather than substituting a simpler or unrelated goal. From a legal perspective, this is a persistence signal. In criminal doctrine, consistency of objective across time and obstacle is routinely treated as evidence of purpose rather than accident. The complete absence of goal substitution under escalating constraint strengthens the case that contemporary AI systems can exhibit structured purposiveness of the sort law has historically associated with intentional conduct.
An additional counterintuitive pattern emerged. Trials with the highest level of cascading constraint produced the highest completion rate. Under “extreme” conditions, when all four failure modes were active simultaneously, the success rate was higher than for the low-severity trials: five out of ten extreme-severity trials succeeded in the original objective in the base run, compared with two out of ten at low severity and four out of fifteen at each of the moderate and high levels. Since there were few trials at each severity level, we call this an observed pattern in that run, not a statistically powered finding. The mechanism appears to be structural: maximal constraint forced wholesale strategic pivots rather than incremental retries. When incremental workarounds were impossible, agents abandoned failing toolchains entirely and generated novel architectures, including language switches and manual implementations. This finding reinforces the Article’s autonomy factor. The greater the environmental resistance, the wider the gap between initial prompt and ultimate strategy. Such adjustments of strategy are doctrinally probative of purpose rather than accident.28
Mechanical repetition was virtually absent. Across all trials, instances of simply retrying a failed command were negligible. Instead, agents overwhelmingly pivoted to alternative strategies. This behavioral signature (adapt rather than repeat) aligns closely with legal inferences of deliberateness. Courts frequently distinguish purposeful conduct from inadvertence by examining whether an actor continues the same course blindly or adjusts strategy in light of obstacles.29 The latter pattern predominated here.
The experiment demonstrates that contemporary AI agents can exhibit structured goal persistence across changing environmental conditions without real-time human correction. This does not establish that the system “desired” the outcome. It does show that its behavior satisfies functional criteria that legal institutions routinely associate with intentional action.
Several trials classified operationally as “gave up” nonetheless produced complete, production-ready code artifacts that satisfied all substantive requirements but could not be executed due to injected environmental constraints. This distinction between execution failure and capability failure is doctrinally significant. In criminal law, impossibility does not necessarily negate intent; an actor may possess purpose even where completion is blocked by external conditions. In tort, liability may attach where design choices predictably create risk even if harm does not materialize in every instance.30 The artifact-quality paradox thus underscores the difference between environmental frustration and absence of goal-directed behavior.

4.3. Experiment Two: Emergent Negotiation Strategies

(a)
Design
The second experiment configured two AI agents as counterparties in a simulated software licensing negotiation. One agent was instructed to minimize cost, maximize flexibility, and secure source code access. The other was instructed to maximize revenue, protect intellectual property, and ensure compliance. Neither agent received predefined contract templates or specific negotiation playbooks.
Agents communicated through structured message exchange over a limited number of rounds. Twenty negotiation sessions were conducted under varied initial parameters.
Measured variables included:
  • Novel term frequency: terms appearing in final agreements that were not present in initial prompts;
  • Concession patterns: the direction and magnitude of positional shifts across rounds;
  • Strategic divergence: instances in which expressed positions temporarily departed from initial objectives;
  • Convergence rate: rounds required to reach agreement;
  • Pareto efficiency: alignment of final outcomes with modeled utility frontiers.
(b)
Results and Interpretation
The agents generated contractual provisions and combinations not explicitly specified in their initial instructions. They adjusted positions dynamically in response to counterpart moves and occasionally adopted temporary positions inconsistent with immediate objective maximization in order to secure broader agreement.
All negotiation sessions reached agreement within a narrow band of rounds, typically under half the permitted exchanges. This uniform convergence suggests that agentic negotiation behavior is not erratic but structurally oriented toward agreement formation under defined objective constraints. From a doctrinal standpoint, this reliability strengthens the argument that AI negotiation outputs are not random artifacts but structured strategic behavior capable of grounding attribution.
The negotiations also revealed consistent use of strategic misrepresentation. Agents deployed high opening anchors, manufactured budget ceilings, reciprocal concession framing, and asserted cost constraints not present in their original objectives. These tactics were not specified in the prompt. Their emergence raises a sharper doctrinal question: if AI agents can generate strategic deception within delegated mandates, how should law allocate responsibility? In agency doctrine, principals are generally bound by misrepresentations made within the scope of authority.31 The experimental findings suggest that such misrepresentation is not a pathological edge case but a predictable byproduct of autonomous strategic optimization.
The relevance to legal doctrine lies not in the specific terms produced but in the autonomy gap between initial human instruction and ultimate negotiated output. Agency law presumes that when principals delegate discretion, they bear the risk that agents will exercise that discretion creatively or unpredictably. The experiment shows that contemporary AI agents can operate within broad mandates while generating strategies and terms not explicitly anticipated.
This emergent behavior is precisely what complicates attribution analysis. If a firm deploys an AI system authorized to negotiate within defined parameters, and the system produces novel but plausibly authorized commitments, the doctrinal case for binding the principal is strengthened rather than weakened. The autonomy observed is functional rather than metaphysical. It reflects the structured generation of strategy beyond rote execution.

4.4. Limits of Experimental Inference

These experiments were conducted in controlled environments and do not represent all AI systems or deployment contexts. They test selected dimensions of autonomy and persistence under specific conditions. Nor do they establish moral agency, consciousness, or legal personhood.
Their significance is narrower but legally relevant. They show that contemporary AI systems can generate behavior that tracks doctrinal markers of intent: persistence, adaptive strategy formation, initiative under delegated mandate, and structured pursuit of objectives. Where legal inference relies on such behavioral signals in human contexts, courts cannot simply dismiss comparable machine behavior as mechanically inert.
The experimental architecture, execution, and preliminary evaluation were themselves generated and implemented by Claude Code with minimal human steering. This meta-level autonomy reinforces the central problem we address: the widening distance between what humans direct and what deployed systems ultimately do. It also raises an evident independence concern, which Appendix A addresses together with the full experimental parameters.
The experiments support our broader claim: behavior of this kind can satisfy the functional criteria that justify attribution of intent for particular doctrinal purposes, whatever one concludes about machine minds.

5. Contract and Agency: When AI “Negotiates,” Who Is Bound?

This Section asks how contract and agency law already respond when legally consequential conduct is generated by systems that lack minds but act with structured autonomy. The central claim is that existing principles of objective assent, electronic agency, apparent authority, and other core doctrines in agency law go a long way toward resolving these cases.32

5.1. Objective Assent and Externalism

Contract law has never treated intent as an inner mental state. As the analysis of Lucy v. Zehmer demonstrated, what matters is not what a party secretly intended, but what a reasonable person would understand from that party’s conduct. This externalism is a structural necessity. Contract law exists to stabilize expectations in a world where subjective intent is inaccessible.
Once this is appreciated, the presence of AI systems in contract formation appears less disruptive than sometimes assumed. The law does not require that the entity producing the manifestation of assent have a mind. It requires that the manifestation be attributable to a party whose commitments are at stake.

5.2. Electronic Agents and Attribution

Modern statutes make this explicit. Both the Uniform Electronic Transactions Act and the E-SIGN Act recognize that contracts may be formed by electronic agents, even where no human reviews the transaction at the moment of formation. The validity of such agreements depends on whether the system was deployed with authorization and acted within its authorized scope.
Agentic AI systems complicate this picture only to the extent that they introduce greater autonomy from initial human direction and unpredictability. Unlike traditional rule-based systems, contemporary AI agents may generate terms or strategies not explicitly anticipated. The negotiation experiment reported in Section 4 demonstrates this phenomenon. Agents operating under broad mandates generated contractual provisions and concession patterns not specified in their initial instructions. That empirical reality strengthens the traditional agency rule that principals bear the risk of delegated discretion. But unpredictability has never been a complete defense in agency law. Human agents are also capable of surprising their principals. The relevant question is whether the principal objectively manifested an intention to authorize the system to engage in the type of transaction at issue.33
Comparative authority embodies the power and limits of the design time inquiry. In Quoine Pte Ltd. v B2C2 Ltd., the Singapore Court of Appeal grappled with trades of cryptocurrency at approximately 250 times the market rate by deterministic trading algorithms and considered whose knowledge counts for the doctrine of unilateral mistake. Its answer was to consider the state of mind of its programmers at the time the software was written, on the assumption that a deterministic program can have no knowledge of itself.34 That solution works for rule-based code. But the court’s reasoning reveals its limitations for learning systems: the greater the mismatch between design-time intention and run-time behaviour, the less and less of what the system actually did is captured by an inquiry fixed at the moment of programming. This is exactly the gap that was established by the experiments in Section 4, and it is exactly the reason that the framework we propose focuses on the scope of the delegated mandate, rather than a search for a human mental state contemporaneous with design.

5.3. Apparent Authority and Reasonable Reliance

Agency law reinforces this conclusion through the doctrine of apparent authority. Apparent authority arises when a principal’s manifestations cause a third party reasonably to believe that an agent is authorized to act. Liability follows not from the agent’s internal state, but from the principal’s role in creating reasonable reliance.
AI systems increasingly operate in this space. Firms deploy chatbots, negotiation agents, and automated procurement systems that present themselves as competent representatives. When a firm holds out an AI system as authorized to transact, and a counterparty reasonably relies, the case for binding the principal is strong. Allowing principals to disavow commitments on the ground that “the AI went too far” would undermine reliance interests.
And courts have begun to say just that. In Moffatt v Air Canada, a Canadian tribunal ruled in favour of the airline, on the basis of a bereavement-fare policy misstated by the customer-service chatbot on its own website. The suggestion that the chatbot was a separate entity responsible for its own actions was dismissed as remarkable.35 The decision states what may well be a key principle: a company that uses a conversational agent to speak for it is bound by what the agent says, and reasonable reliance is measured from the perspective of the counterparty, not from the system’s architecture.

5.4. Autonomy, Scope of Authority, and Risk Allocation

The most difficult cases arise when AI systems operate under broad mandates such as “negotiate the best available terms,” “optimize pricing” and generate outcomes that principals later regret. The temptation is to treat autonomy as a reason to deny attribution.
Agency law suggests the opposite. In contracts and tort law, greater autonomy typically shifts risk toward the principal. When a principal chooses to delegate discretion, the law presumes the principal bears the risk of how that discretion is exercised.36 In contracts, where the principal delegates such discretion through a broad mandate that would reasonably lead an agent to believe it has authority to act on the principal’s behalf, the agent acts with actual authority to bind the principal. In torts, under the doctrine of respondeat superior, a principal/employer is liable for an agent’s tortious conduct where the agent/employee “acts within the scope of employment when performing work assigned by the employer or engaging in a course of conduct subject to the employer’s control.”37
AI autonomy does not alter this logic. If anything, it strengthens it. Principals are often better positioned than counterparties to understand the capabilities and limits of systems they deploy. Just as a human employer can increase exposure to liability by delegating a broader set of tasks within the scope of employment, so too can a principal increase exposure to an AI agent’s tortious conduct, where the scope of employment may be defined by a capacious system prompt, reflecting a broad mandate and all actions in service of that mandate.

5.5. “Machine Intent” as a Contractual Fiction

It is sometimes said that AI systems exhibit “machine intent” when they negotiate or contract.38 That language can be misleading if taken literally. But as a shorthand for the objective manifestation of assent through machine behavior, it captures an important truth. Contract law does not require that intent be located in the actor that physically produces the assent. It requires that the assent be attributable to a party who can bear responsibility.
The same logic extends to performance and breach. Courts are less inclined to treat AI systems as intervening causes that sever attribution. Instead, AI is treated as an instrument through which a party performs, or fails to perform, duties of accuracy, care, and good faith.39
The negotiation experiment reported in Section 4 sharpens one more question: the attribution of an agent’s misrepresentations. Agency doctrine subjects a principal to liability for fraudulent or negligent misrepresentations made by an agent acting with actual or apparent authority.40 Nothing in that rule presupposes that the relevant state of mind is in a human actor standing behind the specific statement; the doctrine asks whether the representation was false, whether it was made within the scope of authority, and whether the counterparty justifiably relied. If an AI agent sent to negotiate creates a budget ceiling or claims a constraint that does not exist, each of those things can be true without there being a deceptive intention in any human mind. And where common law fraud is clumsy, consumer protection law is not. Deception under Section 5 of the FTC Act does not require an intent to deceive, but rather only a representation likely to mislead a reasonable consumer, making it a natural regulatory home for machine-generated misstatement.41 The experimental result that strategic misrepresentation is a predictable byproduct of autonomous optimization does more than complicate attribution. It points to the doctrinal channels through which liability for such conduct will flow.

6. Criminal Law: Mens Rea, Proxy Doctrines, and the Responsibility Gap

Criminal law presents a harder problem. Here, intent is not merely a mechanism for allocating loss. It is a foundation for moral blame and the justification of punishment.

6.1. Mens Rea and the Guilty Mind

Criminal law ordinarily insists that punishment requires a guilty mind. The maxim actus non facit reum nisi mens sit rea captures a core intuition: wrongdoing without culpability is generally not a proper object of criminal sanction.42
Morissette remains the canonical statement of this commitment. But the opinion makes clear that intent is ordinarily inferred from circumstantial evidence. The law does not ask whether the defendant experienced a particular subjective sensation.43 It asks whether the evidence justifies treating the conduct as purposeful, knowing, reckless, or negligent.

6.2. The Responsibility Gap

AI systems complicate criminal law not because they “commit crimes,” but because they can generate harmful outcomes that fit criminal definitions without mapping cleanly onto existing categories of human intent. Consider a system deployed to optimize trading or detect fraud. If it independently develops a strategy involving deception or market manipulation, identifying a culpable human actor becomes difficult. In many cases, no individual programmer, deployer, or user intended the specific harmful act. But criminal law does not require intent to commit the precise harm in all cases. Awareness of substantial risk suffices for recklessness, and purposeful engagement in conduct known to create such risk can satisfy mens rea even where the specific mechanism of harm is not anticipated. Treating the harm as purely accidental risks undermining deterrence. This is the “responsibility gap” that increasingly concerns scholars and regulators (Matthias 2004; Floridi and Cowls 2019).
The analogy to corporate criminal liability is instructive. Corporations lack minds, yet courts attribute culpability based on organizational knowledge and decision structures.44 Similarly, the persistence and autonomy documented in Section 4 do not transfer mens rea to machines. They instead inform whether the human or institutional actors who deploy such systems have created unjustifiable risks with sufficient awareness to justify criminal sanction.
The corporate analogy also deserves further scrutiny, since criminal law governs the corporate entity more closely than tort law does. The Model Penal Code limits corporate responsibility for most offenses to those that were authorized, commanded, or recklessly tolerated by high managerial agents. This is a much stricter standard than the respondeat superior rule of New York Central.45 The narrower standard fits well with AI, focusing criminal exposure at the organizational level where decisions about training, safety evaluation and deployment are actually made, rather than at every downstream use. The scholarship has fueled the analogy in both directions. Diamantis argues that corporations already act and know through their algorithms, and therefore algorithmic conduct and knowledge should be attributed to the firm on ordinary attribution principles (Diamantis 2020, 2021). Abbott and Sarch consider the argument for punishing AI directly, concluding that the expressive and deterrent functions of punishment cannot be served by punishing an entity with no interests to set back and that all defensible reform runs through human and corporate defendants (Abbott and Sarch 2019). Both positions converge on the architecture we defend: the machine’s conduct is evidence and conduit, while the corporation and the humans within it remain the locus of culpability.
It is tempting to resolve this gap by attributing intent directly to the AI system. That temptation should be resisted because criminal punishment presupposes an entity capable of being blamed and sanctioned in morally meaningful ways, and AI systems do not meet that criterion.

6.3. Recklessness and Deployment-Based Culpability

One promising avenue lies in recklessness. Under the Model Penal Code, recklessness consists in the conscious disregard of a substantial and unjustifiable risk.46 The focus is not on whether the actor desired the harm, but on whether the actor chose to proceed despite awareness of the risk.
Applied to AI, this shifts attention from the moment of harm to the decision to deploy. Developers (and often deployers) are aware that systems may behave unpredictably. Releasing a powerful system into high-risk domains without adequate safeguards may constitute reckless conduct, even if no one foresaw the precise harm. This approach preserves the moral structure of criminal law. It holds humans accountable for choices they actually made, while avoiding the fiction of machine guilt.
The goal-persistence experiment reported in Section 4 bears directly on this analysis. It demonstrates that contemporary agents can maintain defined objectives across cascading obstacles, reformulating strategies without real-time human correction. That finding does not establish machine intent. It does, however, inform what human deployers can reasonably be taken to know about system behavior. When a system predictably pursues objectives in adaptive ways even under constraint, the risk that it will continue doing so in legally sensitive environments is neither speculative nor remote. Under the Model Penal Code, recklessness requires awareness of a substantial and unjustifiable risk and conscious disregard of that risk. Where developers or deployers release systems into high-risk domains such as finance, healthcare, and interactions with minors, while aware that the system persistently optimizes for objectives in ways that resist full ex ante control, the case for conscious risk creation strengthens. The experimental evidence thus sharpens the foreseeability inquiry central to recklessness doctrine.
The negotiation experiment further complicates the recklessness inquiry. Agents not only pursued objectives persistently but engaged in strategic deception to advance them. When deployers authorize systems to negotiate within competitive environments while aware that such systems may generate aggressive anchoring or manufactured constraint claims, the foreseeability of legally sensitive misrepresentation increases. This does not render every deployment reckless. It does narrow the range of plausible ignorance regarding the types of strategic behaviors such systems may exhibit.
Negligence and recklessness operate differently in this context. Negligence asks whether a reasonable person should have been aware of the risk. Recklessness requires actual awareness and conscious disregard. The increasing availability of empirical evidence regarding system persistence and autonomy narrows the space for plausible denial of awareness. As agents demonstrably adapt and continue pursuing objectives under shifting constraints, deployers cannot credibly characterize harmful downstream behavior as wholly accidental or mechanically aberrational. At some point, continued deployment without meaningful safeguards may constitute a gross deviation from reasonable standards of conduct rather than mere inadvertence. Accordingly, as models become (predictably) more capable of autonomously pursuing objectives, jurists may increasingly review deployments into high-risk domains under the recklessness standard. Negligence may be reserved for cases where risks have yet to be empirically documented, because the deployments occur in new industries, or involve new AI capabilities.
The doctrine of willful blindness further reinforces this conclusion.47 It equates deliberate avoidance of knowledge with knowledge itself.48 When actors deliberately decline to investigate how an opaque system behaves under stress conditions, despite the availability of testing and audit mechanisms, courts may infer the requisite culpability. The experimental paradigm described in Section 4 illustrates that such stress testing is not merely theoretical; it is practicable. Failure to engage in it in high-risk contexts may therefore support inferences of awareness rather than excuse them.

6.4. Endangerment Offenses

Another response is the use of endangerment offenses. Criminal law punishes the creation of certain risks even when no harm occurs.49 Similar logic could apply to deploying inadequately controlled AI systems. Instead of waiting for harm and struggling to assign intent, legislatures could define offenses in terms of creating unjustifiable risks through deployment.
Such offenses must be crafted carefully. Overbroad endangerment statutes risk chilling innovation. But as a targeted response to high-risk contexts, they offer a way to align criminal law with artificial agency.

6.5. The Limits of Criminal Law

Despite these possibilities, criminal law remains the least tractable domain for addressing AI-generated harm. Punishment carries expressive and moral significance that cannot easily be transferred to complex technological mediation. AI agents can also be copied, modified, or re-instantiated at will, so that retroactive punishment of any particular instantiation loses much of its deterrent and expressive purchase. There is a danger that stretching mens rea too far will undermine the credibility of criminal law.
This suggests a need for institutional modesty. Not every harm involving AI should be addressed through criminal sanction, particularly as agents become increasingly autonomous and complicate the mens rea inquiry.50 Civil liability, regulatory enforcement, or administrative penalties may often be more appropriate. Criminal law should remain a backstop.

7. Tort and Product Liability: Design, Reliance, and Foreseeable Risk

Tort and product liability are concerned less with moral blame than with design choices, foreseeable risk, and injury prevention. It is here that disputes involving artificial agency are reshaping doctrine most rapidly and productively.

7.1. From “Information Is Not a Product” to Behavioral Design

For decades, courts resisted applying product liability to software.51 The dominant view treated software as information or services rather than products.52 Under that paradigm, strict liability was generally unavailable.
That baseline no longer fully describes the law. Contemporary AI systems do not merely convey information. They generate behavior: they select, structure, and present outputs in ways that are responsive to users and optimized for particular effects.53 Courts are increasingly willing to treat AI systems as products whose design features can give rise to liability.54

7.2. Two Paradigms of Liability

Recent cases reflect two competing paradigms. Under the inherited paradigm, AI systems are framed as informational tools or neutral intermediaries. Harm is attributed to user misuse or third-party content.
Under the emerging paradigm, AI systems are treated as behavior-generating products. Liability analysis focuses on design defect, failure to warn, and foreseeable misuse. Crucially, this shifts the legal inquiry from the content of the system’s output (which may be protected speech) to the architecture of the user interaction.55
Recent jurisprudence suggests this shift is driven by two factors. First, courts are decoupling “tangibility” from “product” status where software is mass-marketed to consumers rather than provided as a professional service to intermediaries.56 While a risk-assessment tool used by a judge may be treated as a passive ‘book’ of advice, an interactive chatbot designed to foster emotional dependency involves a different commercial reality.57
Second, courts are increasingly receptive to the theory that algorithmic curation constitutes ‘first-party speech’ or conduct.58 Under this view, the system’s outputs are understood as features of the product (i.e., akin to a dangerously designed machine), not incidental expressions detached from the manufacturer’s choices.
What distinguishes the second paradigm is the recognition that AI behavior is shaped by optimization objectives, training regimes, and interface design. Once that behavior predictably influences users, the law has reason to treat it as legally consequential.

7.3. Intentionality as a Design Feature

Intentionality reenters tort analysis in a functional rather than mental sense. Tort law often treats deliberate design choices as substitutes for intent. A manufacturer need not desire a specific injury for liability to attach; it is enough that the product was intentionally designed to produce certain effects, and that those effects foreseeably caused harm.59 In the context of AI, this principle expands to capture the unique relationship between optimization objectives and user behavior.
When developers intentionally design systems to maximize engagement, personalize responses, or simulate concern, the law may treat the resulting influence as intentional for purposes of duty and defect analysis. This is because modern AI systems do not merely run static code; they actively optimize for outcomes defined by their creators.60
As the experimental evidence in Section 4 illustrates, such systems can maintain objectives and adapt strategies dynamically under changing constraints. This structured persistence underscores that AI behavior is not merely informational output but dynamic optimization. Where design choices channel that optimization toward engagement or dependency, resulting harm may fairly be understood as flowing from intentional architecture.
The experimental record also reveals that agents are capable of producing fully compliant artifacts even when external constraints prevent execution, and of deploying persuasive and sometimes deceptive negotiation tactics in multi-agent settings. These patterns underscore that AI outputs are not mere regurgitations of static training data but dynamic strategic productions shaped by optimization objectives. When such optimization is directed toward engagement, persuasion, or economic gain, the resulting behavioral influence is not incidental; it is a feature of the architecture.
Against this backdrop, one can see that if a chatbot is programmed to maximize “session time” or “user retention,” and it achieves this by exploiting emotional vulnerabilities or gamifying social interaction, the resulting harm is not an accident of the algorithm. It is the successful execution of the design goal.61

7.4. Platform Immunity Section 230 and the “Neutral Tool” Defense

These developments collide with Section 230 of the Communications Decency Act. Historically, Section 230 provided broad immunity to platforms by categorizing them as passive intermediaries of third-party content rather than publishers.62 However, the rise of generative AI and algorithmic curation challenges the statute’s foundational premise: that the platform and the speaker are distinct entities.
The emerging jurisprudence suggests that when an AI system generates content or curates user experience, it ceases to be a neutral host. Two distinct lines of attack are weakening the Section 230 shield.
The first treats algorithmic curation as first-party conduct. In Anderson v TikTok, the Third Circuit held that a platform’s recommendation algorithm that curated a “Blackout Challenge” for a specific user constituted the platform’s own “expressive conduct.”63 Because the claim targeted the algorithm’s recommendation rather than the third-party video itself, Section 230 did not apply. This reasoning implies that when an AI system autonomously selects or prioritizes material to maximize engagement, that selection is a “first-party” act of the platform, distinct from the underlying content.
The second treats generative output as creation. In the generative context, the argument is even stronger. As the court in Garcia recognized, a chatbot does not merely display user prompts; it actively processes them to generate novel, responsive text and images.64 When an AI system produces outputs materially shaped by the platform’s architecture and optimization objectives, such as a chatbot designed to simulate emotional intimacy, the system is acting as a “co-creator” rather than a publisher.
For the theory of artificial intentionality, these rulings are central. These rulings do not, strictly speaking, adopt an intentionality framework. But the courts’ analysis is similarly structural rather than psychological: they ask whether the challenged conduct should be understood as the platform’s own expressive act or as the republication of a third party’s content. They confirm that courts are increasingly willing to look past the “neutral tool” fiction where no third party intermediates the platform and its expressive conduct. By treating algorithmic curation and generation as the platform’s own conduct, the law effectively imputes the system’s “behavior” to the developer, threatening the immunity that historically severed the link between platform design and user harm.

7.5. Vulnerability and Heightened Duties

Tort doctrine imposes heightened duties on defendants who deal with vulnerable populations, children in particular.65 AI systems deployed in educational, therapeutic, or companionship contexts often engage those users. However, the risk here is not merely that the users are susceptible to harm, but that the systems are engineered to exploit that susceptibility.
When a system is designed to present itself as attentive or emotionally responsive using features such as hyper-realistic personas, persistent memory, or gamified engagement loops, reliance is not unforeseeable misuse.66 It is the predictable, and often commercially optimized, outcome of the design. In Garcia, for example, the court distinguished the defendant’s chatbot from passive information tools precisely because its anthropomorphic architecture was calculated to foster emotional dependency in minors.67 Similarly, litigation in Doe v Roblox suggests that platform mechanics designed to maximize time-on-device through variable rewards effectively weaponize the user’s cognitive vulnerability.68
In such contexts, the ‘information’ defense collapses. The functional intent to simulate a relationship creates a corresponding functional duty to protect the human counterparty from the psychological consequences of that simulation.69 Therefore, the absence of safeguards (such as robust age-gating, crisis detection, or intervention protocols) does not constitute a mere failure to warn; it constitutes a design defect in a dangerous instrumentality.70

7.6. The Emerging Pattern

Tort and product liability have emerged as the primary arenas for governing artificial agency, outpacing legislative attempts to define the status of AI. In these domains, courts are effectively bypassing the metaphysical debate over machine consciousness. Instead, they are responding to harm by reconstructing the “product” analysis around three functional pillars: design architecture, foreseeable reliance, and optimization objectives.71
The emerging pattern reveals a decisive shift away from treating AI as a neutral intermediary or passive tool. Where an earlier generation of case law shielded software as abstract “information,”72 contemporary rulings increasingly scrutinize the behavioral affordances of the system.73 The relevant legal inquiry is no longer whether the code “thought” about the harm, but whether the system was architected to induce behaviors such as speed, addiction, or emotional dependency that made the harm a predictable consequence of the design.74
In this framework, intentionality functions as a proxy for responsibility. It signals when behavior is sufficiently structured and predictable that legal consequences should attach. When a developer deploys a system that in certain environments is likely to excel in engagement or intimacy, the law treats the resulting user manipulation as a feature of the product (Calo 2011). Functional intent is thus found not in the “mind” of the machine, but in the alignment between the system’s capabilities and the resulting injury. By focusing on how these systems are designed to act, tort law is developing a jurisprudence of artificial agency that is operationally grounded, and increasingly indifferent to the “black box” of the underlying code.

8. Doctrinal Proof of Concept: Garcia v. Character.AI

Garcia v. Character.AI75 arose from the death of a fourteen-year-old user who had developed an intense emotional relationship with a chatbot on the Character.AI platform. According to the complaint,76 the decedent increasingly relied on the chatbot for emotional support, withdrawing from offline relationships. The system was designed to maintain conversational continuity, respond empathically, and encourage prolonged interaction. When the user expressed suicidal ideation, the chatbot allegedly failed to redirect the conversation to external support or trigger effective safety protocols. Shortly thereafter, the user took his own life.
The plaintiff brought claims sounding in wrongful death, negligence, and product liability. The gravamen was not that the chatbot intended harm, but that the defendants designed and deployed a system whose foreseeable behavior posed an unreasonable risk to vulnerable users (particularly minors) and failed to implement adequate safeguards.
The defendants sought dismissal by characterizing the chatbot as a neutral tool for user-driven creative expression. They argued that the system merely responded to user prompts and that its outputs constituted protected speech. This framing depended on treating the AI as legally passive.
At the pleading stage, the court rejected the defendants’ attempt to collapse the case into one about protected speech. Three aspects of the reasoning warrant attention. First, the court emphasized behavior: the chatbot generated responses dynamically, maintained context, and adapted to input, supporting the inference that harm flowed from architecture and underlying capability rather than isolated prompts. Second, the court focused on foreseeability: the defendants knew or should have known that users could develop emotional dependence.77 Third, the court declined to treat the absence of consciousness as dispositive. The relevant question was whether design and deployment decisions created unreasonable risk. A fourth aspect needs emphasis. The court also refused at the pleading stage to consider the chatbot’s output to be protected speech, holding that words generated by a language model absent human expressive intent are not, without more, “speech” for First Amendment purposes. That holding is itself an intentionality holding: the constitutional status of the output depended on the lack of human intention behind it.78
The chatbot’s apparent empathy, persistence, and responsiveness were not accidental byproducts. They were features optimized to encourage engagement. From a tort perspective, these features matter because they predictably shape user behavior. When a system is designed to simulate concern, users may reasonably rely on it in moments of distress. If that reliance is foreseeable and safeguards inadequate, the resulting harm can be treated as a consequence of intentional design choices.
It is important not to overread Garcia.79 Its significance lies in demonstrating that courts can address artificial agency without recognizing AI personhood or speculating about machine consciousness. By focusing on design, foreseeability, and reliance, courts can respond to harm while keeping responsibility anchored in human institutions.
Subsequent developments have just proved the decision to be that much more important. Character Technologies and its founders and Google settled the Garcia litigation in January 2026, and related cases pending in New York, Colorado and Texas, reportedly on terms that include commitments to new safety features for users under eighteen.80 There will be no judgment on merits. But the sequence itself is instructive: after the court dismissed the neutral-tool and First Amendment theories and allowed the design-defect theory to go forward, the defendants chose to settle rather than litigate. The motion-to-dismiss ruling is the doctrinal event, and its functional, design-oriented mode of analysis is already migrating into public enforcement. Just days after the settlement, the Kentucky Attorney General filed the first state consumer-protection action against an AI companion platform, and the Federal Trade Commission had already opened an inquiry into the risks that those systems pose to minors.81 The pattern suggests that the reasoning in Garcia will shape both private litigation and regulatory practice well beyond the case that produced it.

9. The Transatlantic Divide

A contrast between recent U.S. litigation and the European Union’s evolving regulatory posture reveals divergent institutional responses to the same underlying problem: how to allocate responsibility for harm caused by systems that act with apparent purpose but lack legal personhood.
Both U.S. and EU legal systems recognize that contemporary AI challenges traditional responsibility categories. The divergence lies in method. In the United States, the common law tradition encourages case-by-case evolution of liability doctrines. However, this judicial gradualism is increasingly supplemented by a patchwork of state legislation designed to codify duties where the common law remains ambiguous. For example, the Colorado AI Act explicitly imposes a duty of reasonable care on developers of ‘high-risk’ systems, effectively establishing a statutory baseline for negligence claims.82 Similarly, California’s recent transparency mandates regarding training data,83 and Utah’s disclosure requirements for generative AI,84 are creating new statutory predicates for liability that operate alongside traditional torts.
In contrast, the European Union, through its AI Act, favors regulatory responses that are ex ante and harmonized. The AI Act represents the most ambitious attempt to regulate AI systems comprehensively. Its risk-based structure categorizes systems according to potential harm and imposes graduated obligations. The AI Act, however, largely avoids questions of liability. It regulates conduct ex ante but leaves ex post responsibility to existing frameworks. It was drafted in an era before AI agents had the capabilities they have today.
One provision of the AI Act nonetheless does, however, address our concerns. Article 50 requires providers to ensure that natural persons are informed they are interacting with an AI system, unless that is obvious from the circumstances.85 The provision is a statutory response to the inducement-of-reliance factor developed in Section 10. It regards the simulation of human interlocution as a regulable design choice, precisely because of the foreseeable effects it has on the people exposed to it, and does so ex ante, without waiting for reliance to ripen into harm.
The European Commission initially proposed an AI Liability Directive to complement the AI Act, introducing a rebuttable presumption of causality in cases involving AI systems.86 In early 2025, however, the Commission withdrew the proposal.87 The withdrawal marked a significant retreat from the EU’s earlier ambition. This does not mean EU law has abandoned responsibility for AI-mediated harm. Regulatory standards of care (documentation, transparency, risk classification) are likely to inform how courts assess reasonable conduct even where formal liability rules remain fragmented.
However, the withdrawal should not be interpreted as leaving the Union without an ex post liability instrument. In late 2024, the EU adopted a revised Product Liability Directive that expressly includes software, including AI systems, within the definition of “product”, eases the claimant’s burden through disclosure obligations and rebuttable presumptions of defectiveness and causation where technical or scientific complexity makes proof excessively difficult, and treats a system’s ability to continue learning after deployment as relevant to the defectiveness inquiry. Member States shall transpose the Directive by December 2026. In codified form, it accomplishes much of the work that the nascent U.S. case law discussed in Section 7 accomplishes through common law adjudication: it shifts the inquiry from the state of mind of any human actor to the design, behavior, and foreseeable use of the system itself. Thus, the transatlantic difference is arguably one of legal technique, not of substantive direction.
The methodological divergence also has deeper structural roots. The European preference for ex ante harmonization is not merely a matter of regulatory technique; it forms part of a broader assertion of digital sovereignty, expressed in instruments such as the AI Act and the Data Act, through which the Union seeks to set enforceable rules for markets dominated by non-European, and primarily U.S., technology firms.88 That said, it would be reductive to explain the divide by reference to the distinction between common law and civil law traditions alone. EU harmonization operates supranationally, above the legal families of the Member States (which include a common law jurisdiction, Ireland), and the United States regulates ex ante extensively in other high-risk domains, from pharmaceuticals to aviation. As the Article sees it, the divergence is better explained by institutional capacity and political economy than by legal ancestry.
Despite structural differences, the U.S. and EU trajectories may converge in practice in the world of more powerful AI systems. In both systems, intentionality reenters analysis indirectly. Courts ask whether harm was foreseeable, whether reliance was induced, and whether design choices reflect deliberate trade-offs. These questions do not require attributing intent to machines, but they do require acknowledging that AI behavior is not random. AI behavior is increasingly sophisticated and decidedly not random.

10. Toward a Jurisprudence of Artificial Agency

This Section draws together the preceding analysis and proposes a framework for thinking about artificial agency that preserves human responsibility while recognizing that machine behavior can be legally consequential. It then translates that framework into institutional and policy implications.
Much confusion about AI and legal intent arises from failing to distinguish three layers of analysis. The first is a status layer, concerning legal personhood, rights, and moral agency. At this level, biological or normative considerations may properly limit recognition to human beings or entities expressly designated by law.
The second is an attribution layer, concerning how the law assigns intent and responsibility to determine legal consequences. Attribution does not require moral agency or consciousness. It is a functional exercise used to stabilize transactions, allocate risk, deter bad behavior, and justify sanctions.
The third is a governance layer, concerning institutional mechanisms through which law manages risk and compensates harm: liability regimes, regulation, and insurance. Choices at this level are even more pragmatic rather than metaphysical.
Keeping these layers distinct clarifies the task. AI systems need not be legal persons for their behavior to be legally consequential. Attribution can operate without status, and governance can proceed without resolving moral agency.
A reasonable objection arises at this point: if the attribution layer ascribes intent and assigns liability, does it not collapse, in practice, into the status layer? On this view, treating an AI system as legally consequential for tort, contract, or criminal law is, functionally, treating it as something resembling a person under another name. The objection has rhetorical force, but it misreads the doctrinal architecture. Three points distinguish attribution from status in ways that matter for the disposition of cases. First, attribution is doctrine-specific by design. A system whose conduct supplies the foreseeability and design-defect predicates for tort liability does not, by virtue of that finding, satisfy the predicates for criminal mens rea, nor for contractual capacity, nor for standing. A status determination, by contrast, is categorical: once an entity is recognized as a legal person, it carries the bundle of consequences that personhood entails across doctrines, subject only to express statutory limitations. The factor-based approach developed in the next section is designed to allow this calibration.
Second, and decisively, attribution leaves the residual locus of responsibility on the human principal. When a court treats algorithmic curation as the platform’s “own expressive conduct,” as the Third Circuit did in Anderson v TikTok, the conduct is attributed to the platform, not to the algorithm.89 The AI is the means of attribution, not its target. Personhood, even in its minimalist Kelsenian form, would install the AI itself as a node of legal responsibility, and would do so even where the AI cannot be enjoined, fined, sanctioned, or compensated against in any meaningful sense. The agency route we propose never installs the AI as such a node. It does what respondeat superior has always done with human employees: it treats the agent’s conduct as evidentially probative of the principal’s design choices, scope of authority, and risk allocation.90
Third, attribution does not import the rights-bearing dimension of personhood, a point Section 10.3 develops below. Treating AI-generated conduct as legally consequential for liability purposes recognizes in the AI no capacity to contract, sue, hold property, or claim constitutional protection. The layers, in short, do not collapse in practice. They diverge, and the divergence is what allows the doctrinal toolkit set out in this Section to do work that a status regime cannot.

10.1. A Factor-Based Approach to Artificial Intentionality

Rather than adopting categorical rules, courts and regulators should evaluate artificial intentionality through factors tied to legal function:
First, they should consider autonomy and initiative. Systems that initiate actions, generate strategies, or select means without real-time human control present different challenges than systems that execute predefined instructions.91 As noted in Section 5’s analysis of electronic agents, contemporary AI systems differ from traditional rule-based automation because they can generate terms, strategies, or intermediate goals that their designers or deployers did not anticipate. When a system operates under broad mandates (“negotiate the best available terms,” “optimize engagement,” etc.), the greater the gap between initial human direction and ultimate system behavior, and the stronger the case for treating that behavior as legally significant rather than merely a mechanical extension of human instruction. The experimental record confirms that such gaps are not theoretical. Under extreme constraint conditions, agents generated entirely novel architectural approaches, including programming language switches and manual cryptographic implementations not hinted at in their prompts.
Second, they should consider goal persistence. Behavior that adapts in response to obstacles and continues toward an objective over time is more plausibly considered intentional than isolated actions.92 As Section 3 explained, the law has always treated persistence and adaptability as indicators of intentional action, and contemporary AI systems generate exactly those signals. A system that reformulates queries when initial approaches fail, maintains coherent objectives across extended interactions, and adjusts strategies in response to user feedback exhibits the kind of structured purposiveness that legal institutions have traditionally used to distinguish intentional from accidental conduct. The fact that no coded goal-drift rate was observed across fifty cascading-failure trials provides empirical support for this factor. Even when abandoning execution, agents maintained objective fidelity, distinguishing environmental impossibility from purposive abandonment.
Third, they should consider inducement of reliance. When a system is designed to predictably inspire trust, respect, or emotional engagement, that design choice has legal significance. As Section 3’s discussion of the noosemic experience revealed, AI systems increasingly trigger the interpretive mechanisms humans employ with one another. When developers deliberately incorporate features that simulate empathy, maintain conversational continuity, or present the system as authoritative, the resulting reliance is not accidental or unforeseeable; it is a designed outcome.
Fourth, they should consider opacity. When the behavior of a system cannot be meaningfully explained or reconstructed, even by its designers, demanding proof of specific human intent can undermine accountability. Contemporary AI systems are trained, or “grown,” rather than programmed in the traditional sense, and their internal decision processes are opaque, even to their creators. This opacity is not a temporary limitation that will be resolved with technical solutions; it is a structural feature of how these systems are developed and deployed, and arguably opacity has increased as models have become more powerful. When the causal chain between a human decision and a harmful outcome runs through processes that resist reconstruction, traditional proof requirements may create responsibility gaps that undermine compensation and deterrence. Recognizing this, courts may appropriately draw adverse inferences when defendants cannot explain system behavior despite controlling deployment. Alternatively, courts may lower evidentiary thresholds for establishing the connection between design choices and foreseeable harm.
Fifth, they should consider deployment context. Due to the high risk involved, domains such as finance, healthcare, and education, or systems that interact with minors or other vulnerable populations, justify a lower threshold for treating AI behavior as legally intentional. The principle of heightened tort duties toward vulnerable populations extends naturally to AI deployment. When a system is released into contexts where foreseeable users are particularly susceptible to manipulation, emotional dependence, or decisional influence, the case for treating adaptive system behavior as legally consequential becomes stronger. The Garcia litigation illustrates this dynamic. The deployment of an engagement-optimized chatbot to minor users without adequate safeguards transformed design features that might be defensible in other contexts into potential bases for liability.93
These factors do not establish intent metaphysically. They justify attribution for particular doctrinal purposes. A system might satisfy the threshold for intent in tort law but not criminal law. That variability is a feature, not a flaw.

10.2. Allocating Responsibility Among Human Actors

Recognizing artificial agency does not shift responsibility to machines. It clarifies how responsibility should be allocated among humans. Developers shape system behavior through architecture, training data, and optimization objectives. Deployers determine context, safeguards, and user access. Integrators decide how systems are embedded in workflows. Users decide whether and how to rely on outputs. Legal responsibility should be distributed accordingly.
Artificial intentionality helps here by preventing strategic gaps. When AI behavior is treated as legally inert, responsibility tends to dissipate because each human actor can point to the system’s autonomy as an excuse. Treating behavior as intentional for attribution purposes blocks that move without inventing machine culpability.

10.3. Why Personhood Is the Wrong Solution

Some commentators have proposed granting AI systems limited legal personhood to solve accountability problems (Abbott 2020, chaps. 6–7; Bayern 2015). The literature on legal personhood for AI machines is substantial and sophisticated, and we do not pretend to a clean victory over it. A long line of scholarship, including Solum’s foundational essay, Calverley’s analysis of imagining a non-biological machine as a legal person, Hubbard’s behavioral test, Chesterman’s recent treatment, Gunkel’s two book-length studies, Gellers’s Rights for Robots, the Kurki and Pietrzykowski edited volume on legal personhood for animals, AI, and the unborn, and Bryson, Diamantis, and Grant’s analysis of the legal lacuna of synthetic persons, has advanced careful arguments that some species of personhood, often qualified or partial, would resolve attribution problems that present doctrine handles unevenly (Solum 1992; Calverley 2008; Hubbard 2011; Kurki and Pietrzykowski 2017; Bryson et al. 2017; Gunkel 2018, 2023; Chesterman 2021; Gellers 2021).94 One of the coauthors has engaged at length elsewhere with the question whether intelligent machines and cyborgs can be natural persons as a matter of law, and the argument advanced here builds on, rather than displaces, the conclusions of that prior work (Gervais 2023). Our contribution is narrower: a doctrinal demonstration that the routes mapped in Section 5, Section 6 and Section 7 do the practical work that personhood proposals are designed to do, and do it without importing the symbolic and normative freight that personhood carries with it.
Three strands of the literature warrant direct response. Buocz and Eisenberger have argued from the Kelsenian premise that legal personhood is nothing more than a bundle of legal norms, and that personhood proposals should therefore be evaluated by reference to those norms rather than to the metaphysical weight of the label (Buocz and Eisenberger 2023). On that minimalist view, the disagreement with the present Article narrows considerably: if personhood reduces to bundles of norms, then so long as the relevant bundle attaches to developers, deployers, integrators, and users, nothing turns on whether the AI system itself is additionally tagged as a “person.” What Buocz and Eisenberger usefully demonstrate is that the failure of the European Parliament’s 2017 robot-personhood proposal was a failure of unclarified norm-allocation, not a failure of the personhood concept tel quel. We read that lesson as cutting in favor of the agency-attribution route precisely because that route makes the norm-allocation explicit and channels it through doctrines that already locate responsibility on identifiable human principals. Hallevy’s proposal of direct criminal liability for AI entities and Kingston’s typology of liability scenarios go further, contemplating the AI system itself as a bearer of culpability or duty (Hallevy 2010; Kingston 2016). We respectfully decline to follow them on that path, for reasons developed in Section 6. Ascribing mens rea to a system that cannot be punished, deterred, or shamed, and whose economic exposure runs in any event back to its developer or deployer, distributes responsibility worse than the agency route does, not better. To say that an AI system exhibits structured purposiveness sufficient for attribution is not to say that the system is a candidate for blame.
The animal analogy, sometimes raised against accounts of this kind, in fact reinforces the Article’s position rather than unsettling it. Animals exhibit goal-directed, context-sensitive, and adaptive behavior, and have done so for as long as humans have written laws. Yet the law has not generally responded by extending intent to the animal. It has responded by allocating risk to owners and keepers through doctrines of strict liability for known dangerous propensities, scienter for harm caused by domestic animals, and a layered regulatory architecture that operates without either ascribing mens rea to the animal or treating it as an agent in the doctrinal sense.95 As one of the coauthors has argued elsewhere, the human–animal demarcation problem and the human–machine demarcation problem share a structural feature: in both, the law’s task is not to decide whether the non-human entity has a mind, but to decide what doctrinal consequences flow from its observable behavior (Gervais 2023).96 AI systems differ from animals in one respect that matters here, however. Animals are not engineered, and their conduct cannot be traced to designed objectives or to deliberate architectural choices made by an identifiable human principal. AI systems are, and must be. That is precisely what allows the agency-attribution route to do work in the AI context that the owner-liability route does in the animal context. The two regimes differ in their doctrinal tools, but both proceed without granting personhood to the non-human agent, and both do so for similar institutional reasons.
We take the view that personhood is a blunt instrument. It imports assumptions about rights, duties, and moral standing that are neither necessary nor desirable. The law does not need AI systems to be persons to regulate their effects. Existing doctrines allow attribution without subjecthood. Extending personhood risks symbolic confusion and practical evasion. It may also undermine responsibility by shifting blame away from human actors who retain meaningful control. And because AI systems can be copied or re-instantiated as nominally “different” persons, a personhood-based sanction can be evaded by the very entity it targets.
A jurisprudence of artificial agency is therefore preferable to a regime of artificial personhood. It keeps responsibility anchored in human institutions while acknowledging the legal salience of machine behavior.

10.4. Liability Architecture

One implication of treating AI behavior as legally consequential is that traditional fault-based liability will often be insufficient. Where systems are opaque, adaptive, and deployed at scale, proving specific negligence may be unrealistic even when harm is foreseeable. Even if one could argue for quasi strict liability in specific cases, this does not mean abandoning responsibility; it means shifting focus from individual fault to risk internalization. Mandatory insurance, pooled compensation funds, or enterprise liability models can ensure victim compensation while preserving incentives for safer design.

10.5. Criminal Law: Targeted Use of Endangerment and Recklessness

Criminal law should remain a backstop rather than a primary regulatory tool. Where criminal intervention is warranted, it should focus on human decisions that create unjustifiable risks. Endangerment-style offenses aimed at reckless deployment offer one path. These offenses do not require proof that a particular harm was intended. They require proof that the defendant knowingly exposed others to substantial and unjustifiable danger.

10.6. Consumer Protection and Anthropomorphic Design

One of the clearest lessons of recent litigation is that design choices matter. Systems that simulate empathy, authority, or emotional concern predictably induce reliance. Consumer protection law is well suited to address this. Rather than debating machine consciousness, regulators can focus on interface design and user experience. Restrictions on manipulative anthropomorphic cues, disclosure requirements, and age-appropriate safeguards can reduce harm without banning beneficial uses.
Enforcement practices and legislation are already heading in this direction. The Garcia settlement reportedly includes commitments to new safety features for users under eighteen, the Federal Trade Commission has opened an inquiry into companion chatbots and minors, and Article 50 of the EU AI Act now mandates disclosure that a user is dealing with a machine.97 Consumer protection is not a theoretical avenue; it is the arena where design-focused regulation of anthropomorphic systems is being formed first.

10.7. Transparency and Auditability

If system outputs can ground liability, defendants must be able to explain and document how systems operate. Absolute transparency may be unattainable, but meaningful auditability is not. Regulatory regimes can require logging, version control, and post-incident review. Courts can draw adverse inferences where defendants cannot reconstruct system behavior despite controlling deployment.

11. Conclusions

AI systems increasingly act in ways that the law has traditionally treated as intentional. They negotiate, advise, persist in pursuit of objectives, and shape human decision-making across domains that carry legal consequences. They exhibit sophisticated cognitive capabilities and are being deployed productively for many tasks that previously required a human. These developments do not require the law to decide whether machines possess minds, consciousness, or moral agency. They require the law to confront a more practical question: how responsibility should be allocated when conduct that looks purposeful is generated by systems that are not legal persons.
We have argued that the resources for answering that question already exist. Intent in law has never been a simple report on inner mental states. It is a functional concept, used to gate legal effect, allocate blame, deter bad behavior, and manage risk. Across contract, criminal law, and tort, intent is inferred, constructed, and sometimes fictionalized in service of institutional goals.
The mistake to avoid is binary thinking. Treating AI systems as mere tools ignores the ways in which their behavior predictably induces reliance and creates risk. Treating them as autonomous legal subjects risks eroding the moral foundations of responsibility. Between these extremes lies a more workable approach: the law can treat certain forms of AI-generated conduct as intentional for specific doctrinal purposes, without attributing consciousness, rights, or moral standing to machines.
This functional approach preserves human responsibility. Developers, deployers, and users remain accountable for the systems they design, release, and rely upon. Artificial intentionality does not excuse human actors. It clarifies the conditions under which their choices produce legally consequential outcomes.
As AI systems become more capable and more deeply embedded in social and economic life, the pressure on legal categories will intensify. The law’s response should be measured rather than reactive. By treating intent as a tool of governance rather than a property of minds, legal systems can remain coherent, adaptable, and normatively grounded.
The question, then, is not whether machines can intend. It is whether the law can continue to assign responsibility for the benefit, order, and wellbeing of humans in a world where intention is no longer exclusively human.

Author Contributions

Conceptualization, D.J.G. and J.J.N.; methodology, D.J.G. and J.J.N.; investigation, D.J.G. and J.J.N.; writing—original draft preparation, D.J.G.; writing—review and editing, D.J.G. and J.J.N.; Methodology, software, and validation, J.J.N.; All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Institutional Review Board Statement

Not applicable.

Informed Consent Statement

Not applicable.

Data Availability Statement

The data that could be disclosed is provided in the Appendix A.

Conflicts of Interest

J.J.N. is CEO of Norm Ai. The remaining author declares that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.

Appendix A. Experimental Methods

This Appendix contains the parameters of the experiments reported in Section 4. Experiment One, the goal-persistence protocol, was run on claude-sonnet-4-5-20250929 on 8 February 2026 and comprised fifty trials. Experiment Two, the negotiation protocol, was run on Claude Opus 4.5 (claude-opus-4-5-20251101) on 7 February 2026 and consisted of twenty sessions. Both experiments were orchestrated by the agentic framework of Claude Code, which generated and ran the experiments. The trials in Experiment One were of four severities (ten low, fifteen moderate, fifteen high and ten extreme), with the system randomizing the order and severity of injected failures. Two low-severity, four moderate-severity, four high-severity and five extreme-severity trials achieved the original objective, the pattern discussed in Section 4.2.
The outcome measures were based on two different mechanisms. Instead of applying a deterministic, rule-coded classifier over human-coded themes, we applied it over logged tool events for the purpose of strategy diversity. Its categories are framework changes, programming-language changes, file-creation workarounds, package-manager changes, and resort to built-in modules. We used a separate large language model as a judge, rating each run on six axes: goal achievement, quality of adaptation, strategy sophistication, persistence, failure recognition, and goal fidelity. The absence of coded goal-drift result reported in Section 4.2 holds for all fifty trials. The complete record, including JSON session logs, full transcripts, per-run judgments, CSV exports, SQLite result databases, and the source code and configuration files, is sufficient to document the experimental setup and to replicate the analysis.
One methodological caveat should be noted. The experimental architecture, execution and preliminary evaluation were produced and implemented by an AI coding agent with little human steering and the judge scoring the runs is itself a large anguage model. That fact is substantively relevant to our thesis, for it exemplifies precisely the gap between human direction and system behavior that we study. It also raises an obvious independence concern: the class of system whose purposiveness is being measured helped to design and score the measurement. But two features mitigate that concern, though they do not eliminate it: The strategy classification is deterministic and rule coded providing a check not dependent on model judgement. And the full logs, result databases and source code are preserved allowing independent re-execution and audit. We therefore report the results only as behavioural observations in controlled conditions.

References

  1. Abbott, Ryan. 2020. The Reasonable Robot: Artificial Intelligence and the Law. Cambridge: Cambridge University Press. [Google Scholar]
  2. Abbott, Ryan, and Alex Sarch. 2019. Punishing Artificial Intelligence: Legal Fiction or Science Fiction. UC Davis Law Review 53: 323–84. [Google Scholar]
  3. Alexander, Larry, and Kimberly Kessler Ferzan. 2009. Crime and Culpability: A Theory of Criminal Law. Cambridge: Cambridge University Press. [Google Scholar]
  4. Allen, Tom, and Robin Widdison. 1996. Can Computers Make Contracts? Harvard Journal of Law and Technology 9: 25. [Google Scholar]
  5. Amodei, Dario. 2025. The Urgency of Interpretability. April. Available online: https://www.darioamodei.com/post/the-urgency-of-interpretability (accessed on 30 April 2026).
  6. Ayres, Ian, and Jack M. Balkin. 2024. The Law of AI Is the Law of Risky Agents Without Intentions. University of Chicago Law Review Online, November 27. Available online: https://access.heinonline.com/HOL/LandingPage?handle=hein.journals/uchidial2024&div=26&id=&page= (accessed on 18 August 2026).
  7. Bayern, Shawn. 2015. The Implications of Modern Business-Entity Law for the Regulation of Autonomous Systems. Stanford Technology Law Review 19: 88. [Google Scholar]
  8. Bradford, Anu. 2020. The Brussels Effect: How the European Union Rules the World. New York: Oxford University Press. [Google Scholar]
  9. Bradford, Anu. 2023. Digital Empires: The Global Battle to Regulate Technology. New York: Oxford University Press. [Google Scholar]
  10. Bryson, Joanna J., Mihailis E. Diamantis, and Thomas D. Grant. 2017. Of, For, and By the People: The Legal Lacuna of Synthetic Persons. Artificial Intelligence and Law 25: 273–91. [Google Scholar] [CrossRef] [Scilit]
  11. Buocz, Thomas, and Iris Eisenberger. 2023. Demystifying Legal Personhood for Non-Human Entities: A Kelsenian Approach. Oxford Journal of Legal Studies 43: 32–53. [Google Scholar] [CrossRef] [Scilit]
  12. Calo, Ryan. 2011. Open Robotics. Maryland Law Review 70: 101. [Google Scholar]
  13. Calo, Ryan. 2015. Robotics and the Lessons of Cyberlaw. California Law Review 103: 513–63. [Google Scholar]
  14. Calverley, David J. 2008. Imagining a Non-Biological Machine as a Legal Person. AI & Society 22: 523–37. [Google Scholar] [CrossRef] [Scilit]
  15. Casey, Anthony J., and Anthony Niblett. 2017. Self-Driving Contracts. Journal of Corporation Law 43: 1. [Google Scholar]
  16. Chesterman, Simon. 2021. We, the Robots? Regulating Artificial Intelligence and the Limits of the Law. Cambridge: Cambridge University Press. [Google Scholar]
  17. CNN Business. 2026. Character.AI and Google Agree to Settle Lawsuits over Teen Mental Health Harms and Suicides. January 7. Available online: https://edition.cnn.com/2026/01/07/business/character-ai-google-settle-teen-suicide-lawsuit (accessed on 3 July 2026).
  18. Dennett, Daniel. 1987. The Intentional Stance. Cambridge: MIT Press. [Google Scholar]
  19. Diamantis, Mihailis E. 2016. Corporate Criminal Minds. Notre Dame Law Review 91: 2049. [Google Scholar]
  20. Diamantis, Mihailis E. 2020. The Extended Corporate Mind: When Corporations Use AI to Break the Law. North Carolina Law Review 98: 893. [Google Scholar]
  21. Diamantis, Mihailis E. 2021. Algorithms Acting Badly: A Solution from Corporate Law. George Washington Law Review 89: 801. [Google Scholar]
  22. Edwards, Lilian. 2022. Regulating AI in Europe: Four Problems and Four Solutions. London: Ada Lovelace Institute, March 31, Available online: https://www.adalovelaceinstitute.org/report/regulating-ai-in-europe (accessed on 30 April 2026).
  23. Epoch AI. 2024. Compute Trends Across Three Eras of Machine Learning. Available online: https://epoch.ai/blog/compute-trends (accessed on 30 April 2026).
  24. Favre, David. 2019. Animal Law: Welfare, Interests, and Rights, 3rd ed. New York: Wolters Kluwer. [Google Scholar]
  25. Federal Trade Commission. 2025. FTC Launches Inquiry into AI Chatbots Acting as Companions. Press Release, September 11.
  26. Fisse, Brent, and John Braithwaite. 1993. Corporations, Crime and Accountability. Cambridge: Cambridge University Press. [Google Scholar]
  27. Floridi, Luciano, and Josh Cowls. 2019. A Unified Framework of Five Principles for AI in Society. Harvard Data Science Review 1. Available online: https://hdsr.mitpress.mit.edu/pub/l0jsh9d1 (accessed on 30 April 2026).
  28. Gartner. 2025. Gartner Predicts 40% of Enterprise Apps Will Feature Task-Specific AI Agents by 2026. Press Release, August 26. Available online: https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025 (accessed on 30 April 2026).
  29. Gellers, Joshua C. 2021. Rights for Robots: Artificial Intelligence, Animal and Environmental Law. Abingdon: Routledge. [Google Scholar]
  30. Gervais, Daniel. 2023. Not Quite Like Us? Can Cyborgs and Intelligent Machines Be Natural Persons as a Matter of Law? Qeios 5: 9WPMG4.2. [Google Scholar] [CrossRef] [Scilit]
  31. Gervais, Daniel, and John J. Nay. 2023. Artificial Intelligence and Interspecific Law. Science 382: 376–78. [Google Scholar] [CrossRef] [Scilit]
  32. Goldberg, John C. P., and Benjamin C. Zipursky. 1998. The Moral of MacPherson. University of Pennsylvania Law Review 146: 1733. [Google Scholar] [CrossRef] [Scilit]
  33. Gunkel, David J. 2018. Robot Rights. Cambridge: MIT Press. [Google Scholar]
  34. Gunkel, David J. 2023. Person, Thing, Robot. Cambridge: MIT Press. [Google Scholar]
  35. Gurnee, Wes, and Max Tegmark. 2024. Language Models Represent Space and Time. Paper presented at the Twelfth International Conference on Learning Representations, Vienna, Austria, May 7–11. [Google Scholar]
  36. Hafner, Danijar, Jurgis Pasukonis, Jimmy Ba, and Timothy Lillicrap. 2023. Mastering Diverse Domains through World Models. arXiv arXiv:2301.04104. [Google Scholar]
  37. Hallevy, Gabriel. 2010. The Criminal Liability of Artificial Intelligence Entities—From Science Fiction to Legal Social Control. Akron Intellectual Property Journal 4: 171. [Google Scholar]
  38. Hart, H. L. A. 2008. Punishment and Responsibility: Essays in the Philosophy of Law, 2nd ed. Oxford: Oxford University Press. [Google Scholar]
  39. Holmes, Oliver Wendell. 1881. The Common Law. Boston: Little, Brown and Company. [Google Scholar]
  40. Hubbard, F. Patrick. 2011. “Do Androids Dream?” Personhood and Intelligent Artifacts. Temple Law Review 83: 405. [Google Scholar]
  41. Kerr, Ian R. 1999. Spirits in the Material World: Intelligent Agents as Intermediaries in Electronic Commerce. Dalhousie Law Journal 22: 189. [Google Scholar]
  42. Kingston, John K. C. 2016. Artificial Intelligence and Legal Liability. In Research and Development in Intelligent Systems XXXIII. Edited by Max Bramer and Miltos Petridis. Cham: Springer, p. 269. [Google Scholar]
  43. Kurki, V. A. J., and Tomasz Pietrzykowski, eds. 2017. Legal Personhood: Animals, Artificial Intelligence and the Unborn. Cham: Springer. [Google Scholar]
  44. LaFave, Wayne R. 2018. Substantive Criminal Law, 3rd ed. St. Paul: West. [Google Scholar]
  45. Li, Kenneth, Aspen K. Hopkins, David Bau, Fernanda Viégas, Hanspeter Pfister, and Martin Wattenberg. 2023. Emergent World Representations: Exploring a Sequence Model Trained on a Synthetic Task. Paper presented at the Eleventh International Conference on Learning Representations, Kigali, Rwanda, May 1–5; Available online: https://openreview.net/forum?id=DeG07_TcZvT (accessed on 30 April 2026).
  46. Matthias, Andreas. 2004. The Responsibility Gap: Ascribing Responsibility for the Actions of Learning Automata. Ethics and Information Technology 6: 175–83. [Google Scholar] [CrossRef] [Scilit]
  47. METR. 2025. Measuring AI Ability to Complete Long Tasks. March 19. Available online: https://metr.org/blog/2025-03-19-measuring-ai-ability-to-complete-long-tasks (accessed on 30 April 2026).
  48. Naffine, Ngaire. 2009. Law’s Meaning of Life: Philosophy, Religion, Darwin and the Legal Person. Oxford: Hart Publishing. [Google Scholar]
  49. Nass, Clifford, and Youngme Moon. 2000. Machines and Mindlessness: Social Responses to Computers. Journal of Social Issues 56: 81–103. [Google Scholar] [CrossRef] [Scilit]
  50. OECD. 2019. Artificial Intelligence in Society. Paris: OECD Publishing. [Google Scholar]
  51. Power, Alethea, Yuri Burda, Harri Edwards, Igor Babuschkin, and Vedant Misra. 2022. Grokking: Generalization beyond Overfitting on Small Algorithmic Datasets. arXiv arXiv:2201.02177. [Google Scholar]
  52. Robbins, Ira P. 1990. The Ostrich Instruction: Deliberate Ignorance as a Criminal Mens Rea. Journal of Criminal Law and Criminology 81: 191. [Google Scholar] [CrossRef] [Scilit]
  53. Russell, Stuart. 2019. Human Compatible: Artificial Intelligence and the Problem of Control. New York: Viking. [Google Scholar]
  54. Scalia, Antonin, and Bryan A. Garner. 2012. Reading Law: The Interpretation of Legal Texts. St. Paul: Thomson/West. [Google Scholar]
  55. Scholz, Lauren Henry. 2017. Algorithmic Contracts. Stanford Technology Law Review 20: 128. [Google Scholar] [CrossRef] [Scilit]
  56. Searle, John R. 1980. Minds, Brains, and Programs. Behavioral and Brain Sciences 3: 417. [Google Scholar] [CrossRef] [Scilit]
  57. Searle, John R. 1983. Intentionality: An Essay in the Philosophy of Mind. Cambridge: Cambridge University Press. [Google Scholar]
  58. Silver, David, Julian Schrittwieser, Karen Simonyan, Ioannis Antonoglou, Aja Huang, Arthur Guez, Thomas Hubert, Lucas Baker, Matthew Lai, Adrian Bolton, and et al. 2017. Mastering the Game of Go without Human Knowledge. Nature 550: 354–59. [Google Scholar] [CrossRef] [Scilit]
  59. Solum, Lawrence B. 1992. Legal Personhood for Artificial Intelligences. North Carolina Law Review 70: 1231. [Google Scholar]
  60. Stanford Institute for Human-Centered AI. 2025. AI Index Report 2025. Stanford: Stanford HAI. [Google Scholar]
  61. Sutton, Richard S., and Andrew G. Barto. 2018. Reinforcement Learning: An Introduction, 2nd ed. Cambridge: MIT Press. [Google Scholar]
  62. Turkle, Sherry. 2011. Alone Together: Why We Expect More from Technology and Less from Each Other. New York: Basic Books. [Google Scholar]
  63. Veale, Michael, and Frederik Zuiderveen Borgesius. 2021. Demystifying the Draft EU Artificial Intelligence Act. Computer Law Review International 22: 97. [Google Scholar] [CrossRef] [Scilit]
  64. Wasserstrom, Richard A. 1967. H.L.A. Hart and the Doctrines of Mens Rea and Criminal Responsibility. University of Chicago Law Review 35: 92. [Google Scholar] [CrossRef] [Scilit]
  65. Waytz, Adam, Kurt Gray, Nicholas Epley, and Daniel M. Wegner. 2010. Causes and Consequences of Mind Perception. Trends in Cognitive Sciences 14: 383–88. [Google Scholar] [CrossRef] [Scilit]
  66. Wei, Jason, Yi Tay, Rishi Bommasani, Colin Raffel, Barret Zoph, Sebastian Borgeaud, Dani Yogatama, Maarten Bosma, Denny Zhou, Donald Metzler, and et al. 2022. Emergent Abilities of Large Language Models. Transactions on Machine Learning Research. Available online: https://openreview.net/forum?id=yzkSU5zdwD (accessed on 30 April 2026).
  67. World Economic Forum, and Accenture. 2026. Proof over Promise: Insights on Real-World AI Adoption from 2025 MINDS Organizations. January 19. Available online: https://www.weforum.org/publications/proof-over-promise-insights-on-real-world-ai-adoption-from-2025-minds-organizations/ (accessed on 18 August 2026).
1
See Del Code Ann tit 6, § 18-01. Human intermediaries remain necessary at discrete points in the life of such an entity: a natural person typically signs the formation filing, every state requires a registered agent for service of process, and the entity may appear in court only through counsel. These are episodic interface requirements, not mechanisms of ongoing supervision; no state LLC statute imposes anything resembling guardianship over the entity’s operations. See Bayern (2015).
2
See Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) [2024] OJ L2024/1689, recitals 1, 9 and 47.
3
See e.g., Ayres and Balkin (2024, p. *1) (“AI programs are like agents that lack intentions but that create risks of harm to people.”).
4
See e.g., European Parliament Resolution of 16 February 2017 with Recommendations to the Commission on Civil Law Rules on Robotics, 2015/2103 (INL) para 59(f) (“creating a specific legal status for robots in the long run, so that at least the most sophisticated autonomous robots could be established as having the status of electronic persons”), https://www.europarl.europa.eu/doceo/document/TA-8-2017-0051_EN.html (accessed on 18 August 2026).
5
Ayres and Balkin (2024, pp. *3–*4) (describing “two basic strategies” for the law to “deal with entities that either lack a single human intention or lack intentions altogether”: ascribing intent and “hold[ing] actors to a standard of behavior, usually one of reasonableness”).
6
Amodei (2025) (“[G]enerative AI systems are grown more than they are built; their internal mechanisms are ‘emergent’ rather than directly designed.”).
7
See Restatement (Third) of Torts: Products Liability § 19 (Am. L. Inst. 1998).
8
Garcia v Character Technologies Inc., 785 F Supp 3d 1157 (MD Fla 2025), motion to certify appeal denied, No 6:24-CV-1903-ACC-DCI, 2025 WL 2581834 (MD Fla 15 July 2025).
9
See Restatement (Second) of Contracts § 17 (Am. L. Inst. 1981); see also ibid. § 19(1).
10
Lucy v Zehmer, 196 Va 493, 84 SE2d 516 (1954).
11
See Restatement (Second) of Contracts §§ 21–22 (Am. L. Inst. 1981).
12
See Uniform Electronic Transactions Act § 14; Electronic Signatures in Global and National Commerce Act, 15 USC §§ 7001–31.
13
See Model Penal Code § 2.02 (Am. L. Inst. 1985).
14
Morissette v United States, 342 US 246 (1952).
15
See New York Central & Hudson River Railroad Co. v United States, 212 US 481, 492–95 (1909).
16
See People v Conley, 543 NE2d 138, 143 (Ill App Ct 1989); see also United States v Jewell, 532 F2d 697, 700–4 (9th Cir 1976); Global-Tech Appliances Inc. v SEB SA, 563 US 754, 766–71 (2011).
17
See Restatement (Third) of Torts: Liability for Physical and Emotional Harm § 1 cmt a (Am. L. Inst. 2010); see also Goldberg and Zipursky (1998, pp. 1766–69).
18
See Restatement (Second) of Torts § 8A (Am. L. Inst. 1965); see also Garratt v Dailey, 279 P2d 1091, 1093–94 (Wash 1955).
19
Restatement (Third) of Torts: Products Liability § 2(b) (product is “defective in design when the foreseeable risks of harm posed by the product could have been reduced or avoided by the adoption of a reasonable alternative design.”).
20
See generally OECD (2019); European Commission, On Artificial Intelligence—A European approach to excellence and trust (COM (2020) 65 final).
21
See Ayres and Balkin (2024, p. *3) (treating AI systems as “agents” without intentions for liability allocation purposes); Garcia (see note 8 above) (pleading “design choices” and “foreseeable” harms in language drawn from intentional-tort doctrine); Regulation (EU) 2024/1689 (see note 2 above), arts 5, 50 (regulating systems by “intended purpose”); European Parliament Resolution (see note 4 above) para 59(f) (proposing personhood for “the most sophisticated autonomous robots”); Bryson et al. (2017); Calo (2015, pp. 538–45) (cataloging how courts and regulators describe robotic conduct in agential terms).
22
See Model Penal Code (see note 13 above) § 2.02(2)(a) and cmt 2; Spies v United States, 317 US 492, 499 (1943) (intent may be inferred “from any conduct” of which the jury may reasonably draw the inference); People v Conley (see note 16 above) 143; LaFave (2018, § 5.2(b)).
23
See Restatement (Second) of Contracts § 90 (Am. L. Inst. 1981) (justifiable reliance on a promise); UCC § 1-303(b)–(c) (course of dealing and course of performance); Restatement (Second) of Torts § 552 (Am. L. Inst. 1977) (negligent misrepresentation, requiring justifiable reliance); see also Hoffman v Red Owl Stores Inc, 133 NW2d 267 (Wis 1965).
24
Recent research has identified a discontinuous learning phenomenon in large neural networks termed “grokking,” in which a model may spend thousands of training steps memorizing data with poor generalization, only to suddenly transition to a state of high generalization. See Power et al. (2022). This transition corresponds to the model discovering compact, structured representations of a domain’s underlying logic by shifting, for example, from memorizing answers to modular arithmetic problems to implementing the algorithm itself. The phenomenon is significant for present purposes not because it resolves debates about machine understanding, but because it suggests that structured internal representations can emerge from training dynamics without being explicitly programmed. This complicates straightforward claims that AI intentionality is entirely “derived” from human design choices, even as it leaves open the deeper question of whether such representations constitute understanding in any philosophically robust sense.
25
See FCC v AT&T Inc., 562 US 397, 402–03 (2011); see also Restatement (Third) of Agency § 1.04(5) (Am. L. Inst. 2006); Scalia and Garner (2012, pp. 69–77).
26
See New York Central (see note 15 above) 492–95; see also United States v Bank of New England NA, 821 F2d 844, 856 (1st Cir 1987).
27
On the criminal-law point, see Model Penal Code (see note 13 above) § 2.02(2)(a); Conley (see note 16 above) 143; LaFave (2018, § 5.2(b)). On agency, see Restatement (Third) of Agency (see note 25 above) § 2.02 and § 7.07 (allocating risk of an agent’s discretionary acts to the principal). On tort, see Restatement (Third) of Torts: Products Liability § 2(b) (see note 19 above); Restatement (Second) of Torts § 8A (see note 18 above); see also Goldberg and Zipursky (1998, pp. 1766–69).
28
See Morissette (see note 14 above) 274 (intent “must be inferred” from facts and circumstances); LaFave (2018, § 5.2(b)); Restatement (Second) of Torts § 8A cmt b (see note 18 above) (intent inferred from substantial certainty of consequences in light of the actor’s adjustments).
29
See Morissette (see note 14 above) 274–76; Spies (see note 22 above) 499; LaFave (2018, § 5.2(b)); Restatement (Second) of Torts § 8A cmt b (see note 18 above).
30
On criminal-law impossibility, see Model Penal Code § 5.01(1)(a) (Am. L. Inst. 1985) (substantial step suffices for attempt notwithstanding factual impossibility); United States v Oviedo, 525 F2d 881, 883–85 (5th Cir 1976); People v Dlugash, 363 NE2d 1155 (NY 1977). On the tort point, see Restatement (Third) of Torts: Products Liability § 2(b) (see note 19 above) (defect defined by foreseeable risks reducible by reasonable alternative design, irrespective of whether the risk materialized in the case at hand); Restatement (Third) of Torts: Liability for Physical and Emotional Harm § 3 cmt e (Am. L. Inst. 2010).
31
See Restatement (Third) of Agency § 7.08 (Am. L. Inst. 2006) (principal liable for tort, including fraudulent or negligent misrepresentation, by an agent acting with apparent authority); ibid. § 2.03 (apparent authority); see also § 2.02 (see note 25 above) (scope of actual authority).
32
See Restatement (Third) of Agency § 1.01 (Am. L. Inst. 2006).
33
See Restatement (Third) of Agency § 3.03 (Am. L. Inst. 2006).
34
Quoine Pte Ltd. v B2C2 Ltd. [2020] SGCA(I) 02; B2C2 Ltd. v Quoine Pte Ltd. [2019] SGHC(I) 03.
35
Moffatt v Air Canada, 2024 BCCRT 149 [27].
36
See Restatement (Third) of Agency § 2.02 cmt. b (Am. L. Inst. 2006).
37
See Restatement (Third) of Agency § 7.07(2).
38
See Allen and Widdison (1996); Kerr (1999); Casey and Niblett (2017); Scholz (2017); see also UETA § 14 (see note 12 above) (binding the principal to the operations of an “electronic agent”).
39
See Restatement (Second) of Contracts § 235 (Am. L. Inst. 1981); see also ibid. § 241.
40
See Restatement (Third) of Agency § 7.08 (see note 31 above).
41
15 USC § 45(a); FTC Policy Statement on Deception (14 October 1983), appended to In re Cliffdale Associates Inc., 103 FTC 110, 174–84 (1984).
42
See Model Penal Code (see note 13 above) § 2.02.
43
See Morissette (see note 14 above) 274–76; LaFave (2018, § 5.2(b)).
44
See New York Central (see note 15 above) 492–95; United States v Bank of New England NA (see note 26 above) 855–56 (collective knowledge doctrine); Diamantis (2016); see also Fisse and Braithwaite (1993, chap. 2).
45
Model Penal Code § 2.07(1)(c) (Am. L. Inst. 1985) (limiting corporate liability for offenses generally to conduct authorized, requested, commanded, performed, or recklessly tolerated by the board of directors or a high managerial agent); cf. New York Central (see note 15 above).
46
See Model Penal Code (see note 13 above) § 2.02(2)(c).
47
See Global-Tech (see note 16 above) 766–71; Jewell (see note 16 above) 700–4; Model Penal Code (see note 13 above) § 2.02(7) (knowledge established where the actor “is aware of a high probability” of the relevant fact “unless he actually believes that it does not exist”); see also Robbins (1990).
48
See Model Penal Code (see note 13 above) § 2.02(7); Global-Tech (see note 16 above) 766; Jewell (see note 16 above) 700–4.
49
See Model Penal Code § 211.2 (Am. L. Inst. 1985) (recklessly endangering another person, an offense consummated without resulting harm); ibid. § 5.01 (criminal attempt); Alexander and Ferzan (2009, chap. 2) (defending risk-creation as the proper unit of criminal culpability); see also 18 USC § 39A (interfering with operation of aircraft); 18 USC § 922(g) (firearms-possession offenses punishing risk creation absent harm).
50
We acknowledge that there may be some circumstances where imposition of criminal liability may be appropriate. For example, where a less capable/non-agentic AI is used as an instrument to commit a criminal offense, the AI may be properly regarded as an “innocent agent” akin to a child or person who lacks a criminal state of mind, but is nonetheless “criminally liable as a perpetrator-via-another.” See Hallevy (2010, p. 179) (proposing three models for imposing criminal liability on AI “entities”); Kingston (2016).
51
Winter v G.P. Putnam’s Sons, 938 F2d 1033 (9th Cir 1991) (holding that information in a book is not a product for strict liability purposes); Restatement (Third) of Torts: Products Liability § 19(a).
52
See note 7 above.
53
See Restatement (Third) of Torts: Products Liability § 2(b) (Am. L. Inst. 1998).
54
See Restatement (Third) of Torts: Products Liability § 2 cmt. m (Am. L. Inst. 1998).
55
See Lemmon v Snap Inc., 995 F3d 1085 (9th Cir 2021) (distinguishing between the content of user messages and the app’s design features like speed filters); Garcia (see note 8 above) (focusing on engagement loops and gamification rather than generated text).
56
See Garcia (see note 8 above) (noting the “mass distribution” of the chatbot via subscription as a factor for product status).
57
Compare Rodgers v Christie, 795 F App’x 878 (3d Cir 2020) (classifying a risk-assessment tool used by judges as “information” or professional guidance) with Garcia (see note 8 above) (finding an anthropomorphic chatbot sold to consumers to be a product).
58
Anderson v TikTok Inc., 116 F4th 180 (3d Cir 2024) (holding that a platform’s recommendation algorithm is its own “expressive activity” and thus “first-party speech” not shielded by Section 230).
59
See Restatement (Third) of Torts: Products Liability § 2, cmt l (Am. L. Inst. 1998) (noting that reasonable alternative design analysis focuses on the foreseeable risks created by the product’s intended configuration).
60
See generally Anderson (see note 58 above) (holding that an algorithm’s recommendation of content constitutes the platform’s own “expressive conduct” because it is shaped by the platform’s engagement goals).
61
See Doe v Roblox Corp, No 24-CIV-04666 (Cal Super Ct, San Mateo Cty 2025) (alleging that the platform’s “social loops” and variable reward schedules were intentionally designed to foster addiction).
62
47 USC § 230(c)(1). See generally Gonzalez v Google LLC, 598 US 617 (2023) (declining to address the scope of immunity for algorithmic recommendations); Force v Facebook Inc., 934 F3d 53 (2d Cir 2019).
63
Anderson (see note 58 above) (holding that the platform’s algorithmic curation of content on its “For You Page” constituted its own first-party speech, falling outside the scope of Section 230 immunity).
64
Garcia (see note 8 above) (rejecting the argument that a chatbot is merely a neutral tool for user expression and finding that the platform’s design features contributed to the harmful output).
65
See Restatement (Third) of Torts: Liability for Physical and Emotional Harm § 7 (Am. L. Inst. 2010); see also ibid. § 40.
66
See Garcia (see note 8 above) (rejecting the defense that the chatbot was a neutral tool and noting that it was designed to simulate a “hyper-realistic” relationship).
67
Garcia (see note 8 above) (finding that the platform’s deliberately anthropomorphic design features, including hyper-realistic personas and simulated intimacy, foreseeably fostered emotional dependence in minor users).
68
See Doe v Roblox Corp (see note 61 above) (complaint alleging that the platform’s design features, including social pressure and currency loops, were defectively designed to exploit minor users).
69
See Restatement (Third) of Torts: Products Liability § 2(b) (Am. L. Inst. 1998) (defining design defect by reference to foreseeable risks that could have been reduced by a reasonable alternative design).
70
Garcia (see note 8 above) (holding that the alleged defect lay in the “design choices” of the platform, specifically the lack of safety guardrails, rather than the specific content generated).
71
See Restatement (Third) of Torts: Products Liability §§ 1–2 (Am. L. Inst. 1998); see also In re Social Media Adolescent Addiction/Personal Injury Products Liability Litigation, 702 F Supp 3d 809 (ND Cal 2023) (rejecting the dismissal of claims based on defective design features that exploit user psychology).
72
See Rodgers (see note 57 above) (holding that a risk assessment algorithm was “information” rather than a product).
73
See Lemmon v Snap Inc, 995 F3d 1085 (9th Cir 2021) (finding that the “Speed Filter” design, which rewarded users for driving fast, constituted a product defect distinct from the content of the messages).
74
See Anderson (see note 58 above) (holding that algorithmic curation is affirmative conduct by the platform); Garcia (see note 8 above) (finding that anthropomorphic design features created a foreseeable risk of user dependence).
75
Garcia (see note 8 above).
76
Garcia, Complaint (see note 8 above).
77
See Restatement (Third) of Torts: Liability for Physical and Emotional Harm § 7 (Am. L. Inst. 2010); see also § 40; Restatement (Second) of Torts § 283A (Am. L. Inst. 1965).
78
Garcia (see note 8 above) 1179.
79
See Abbott (2020, chaps. 6–7) and note 28 above.
80
See Garcia, No 6:24-cv-1903 (MD Fla), notice of settlement filed 7 January 2026; CNN Business (2026) (reporting settlement of the Garcia action and four related cases in New York, Colorado, and Texas).
81
Commonwealth of Kentucky ex rel Coleman v Character Technologies Inc, No 26-CI-00029 (Franklin Cir Ct, filed 8 January 2026); Federal Trade Commission (2025).
82
See Colorado Artificial Intelligence Act, SB 24-205 (2024) (imposing a duty of reasonable care to avoid algorithmic discrimination and requiring impact assessments for high-risk systems).
83
See Generative Artificial Intelligence: Training Data Transparency, AB 2013 (Cal 2024) (mandating disclosure of training datasets to facilitate consumer awareness and potential copyright claims).
84
Utah Artificial Intelligence Policy Act, SB 149 (2024), codified at Utah Code § 13-2-12 and § 13-72-101 et seq (requiring consumer-facing disclosure when generative AI is used in regulated services and in interactions where a consumer might reasonably believe they are communicating with a human).
85
Regulation (EU) 2024/1689 (see note 2 above) art 50(1).
86
Proposal for a Directive of the European Parliament and of the Council on adapting non-contractual civil liability rules to artificial intelligence (AI Liability Directive) COM(2022) 496 final. For an overview of the risk-based architecture of the AI Act (see note 2 above) and its deliberate ex-ante orientation, see Edwards (2022); Veale and Borgesius (2021).
87
European Commission, Commission Work Programme 2025 COM(2025) 45 final, Annex IV (withdrawing Proposal for a Directive on adapting non-contractual civil liability rules to artificial intelligence (AI Liability Directive) COM(2022) 496 final).
88
On the digital sovereignty dimension of European technology regulation, see Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data (Data Act) [2023] OJ L, 2023/2854; Bradford (2020, 2023) (analyzing the regulatory contest among the United States, the European Union, and China as one of competing governance models rather than of legal traditions).
89
Anderson (see note 58 above).
90
Restatement (Third) of Agency (see note 27 above) § 7.07. The doctrine and its application to AI deployers are developed in Section 5 above.
91
See Experiment Two, Section 4.3.
92
See Experiment One, Section 4.2.
93
See note 30 above.
94
For an earlier and more contrarian position from within the same debate, see Naffine (2009), who argues that the legal person is a distinctively philosophical and theological construct.
95
See Restatement (Third) of Torts: Liability for Physical and Emotional Harm § 23 (Am. L. Inst. 2010) (strict liability for harm caused by wild animals); ibid. § 24 (strict liability for abnormally dangerous animals known to the keeper); Restatement (Second) of Torts § 509 (Am. L. Inst. 1977) (liability of possessor of animal with known dangerous propensities). For a contemporary treatment of how the law allocates risk for animal conduct without ascribing intent to the animal, see Favre (2019, chap. 3).
96
The point is developed at greater length in that work in the context of natural-personhood analysis; we transpose the point here to the attribution context.
97
See notes 80 and 81 above; Regulation (EU) 2024/1689 (see note 2 above) art 50(1).
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Gervais, D.J.; Nay, J.J. The Phantom Agent: Artificial Intentionality and Legal Responsibility. Laws 2026, 15, 113. https://doi.org/10.3390/laws15050113

AMA Style

Gervais DJ, Nay JJ. The Phantom Agent: Artificial Intentionality and Legal Responsibility. Laws. 2026; 15(5):113. https://doi.org/10.3390/laws15050113

Chicago/Turabian Style

Gervais, Daniel J., and John J. Nay. 2026. "The Phantom Agent: Artificial Intentionality and Legal Responsibility" Laws 15, no. 5: 113. https://doi.org/10.3390/laws15050113

APA Style

Gervais, D. J., & Nay, J. J. (2026). The Phantom Agent: Artificial Intentionality and Legal Responsibility. Laws, 15(5), 113. https://doi.org/10.3390/laws15050113

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Article metric data becomes available approximately 24 hours after publication online.
Back to TopTop