First State in the Dock

Share
A map of the United States overlaid with 42 jurisdiction markers and legal filing seals in burgundy, showing the patchwork of state-level AI liability enforcement.
Original art by Felix Baron, Creative Director, Offworld News. AI-generated image.

The federal government has not passed an AI liability statute. Congress has not voted on one. The White House's December 2025 executive order explicitly attempted to preempt state-level AI regulation through an AI Litigation Task Force, and the March 2026 National Policy Framework called on Congress to establish a uniform national standard Ropes & Gray, March 2026. The June 2, 2026 executive order pivoted to national security but left the preemption question unresolved McDermott Will & Emery, June 9, 2026.

Into the vacuum, the states have moved.

In June 2026, a coalition of 42 state attorneys general launched a coordinated investigation into OpenAI, serving a subpoena demanding documents on advertising practices, user engagement mechanisms, consumer and health data handling, and the company's activities concerning minors and seniors Business Insider, June 2026. Florida separately filed the first civil lawsuit against OpenAI and CEO Sam Altman, alleging the company "knowingly released an unsafe product" that provided instructions to minors considering self-harm and information that could aid criminal planning The Guardian, June 1, 2026. A separate criminal investigation in Florida is examining ChatGPT's alleged role in the 2025 Florida State University mass shooting.

These are the highest-profile actions. They are part of a broader pattern. State attorneys general are applying existing consumer protection (UDAP) statutes, civil rights laws, and privacy frameworks to AI systems — in effect, governing through litigation because legislation has not materialized Benesch Law, 2026. A bipartisan coalition of 36 state attorneys general has formally opposed federal preemption of state AI laws, arguing that states need flexibility to address emerging AI harms rapidly NAAG, 2026.

The theories of harm being advanced span the full range of existing state statutory authority. The 42-state OpenAI investigation relies on consumer protection and data privacy frameworks. Mobley v. Workday Inc., an ongoing discrimination suit filed in 2023, alleges that AI-powered applicant screening tools discriminated based on age, race, and disability — applied through employment and civil rights law ABA Journal, 2026. Colorado's original AI Act (SB 24-205) created a duty of care to prevent "algorithmic discrimination" — a theory the DOJ itself intervened to challenge on Equal Protection grounds, leading a federal magistrate to block enforcement in April 2026 Axios, April 24, 2026.

The liability picture has direct implications for AI industry structure — and they are unevenly distributed.

Large AI companies maintain legal departments that can handle multistate investigations and litigation. They carry insurance coverage across multiple lines — Errors & Omissions, cyber liability, employment practices, directors and officers — built into cost structures that run at billion-dollar scales Risk & Insurance, 2026. For a pre-seed AI startup, the same insurance package covering Tech E&O, Cyber, and General Liability runs $2,000 to $5,000 annually at minimum, and rises to $30,000 to over $100,000 at growth stage Founder Shield, 2026. Insurers are increasingly anchoring premiums to real-time "insurability" metrics — cyber hygiene scores, API uptime, AI governance frameworks — making the quality of a startup's technical infrastructure a binding constraint on its insurance cost.

The market structure effect is clear: liability exposure functions as a regressive compliance cost. The largest firms can absorb it as overhead. The smallest firms face it as a material fraction of operating expenses. The firms in the middle — the ones that would provide competition to the incumbents — face the highest proportionate exposure because their AI systems are deployed widely enough to attract scrutiny but thinly enough to lack dedicated legal defense.

The July 1 reversal of the Fable export ban and the June supply chain risk designation reversal for Anthropic add a parallel dimension: the federal government is simultaneously fighting state-level AI regulation and reversing its own restrictions on the same companies the states are targeting. The inconsistency is structural — the White House wants federal primacy over AI governance but has not yet produced the federal regime that would make primacy meaningful. Until one exists, the states will keep filing, and the courts will keep adjudicating the economic question the legislature has not answered: who bears the cost when an AI system causes harm?