01
Attribution chain
The first task is to identify who acted, under whose authority, through which runtime, with what evidence and controls, and whether the action exceeded the grant.
02
Responsibility is not automatically singular
Developers, deployers, principals, operators, issuers, service providers, institutions, and autonomous actors may occupy different responsibility positions. One technical chain does not automatically allocate every legal loss.
03
External law remains decisive externally
Tort, product liability, employment, privacy, financial, criminal, tax, and sector rules are jurisdiction-specific. This site does not generalize one jurisdiction’s doctrine into universal AI liability.
04
Insurance and contractual allocation
Insurance, indemnity, limitation clauses, warranties, governance requirements, and audit records can allocate risk, but mandatory law and third-party rights can constrain private allocation.
05
Evidence for dispute resolution
Logs, provenance, delegation records, credentials, runtime evidence, notices, and corrections can improve proof. Cryptographic integrity does not itself determine legal relevance or fault.
06
Attribution remains state-scoped
Texas and Delaware UETA provisions, like the existing California/Illinois records, make attribution context-dependent and subject to other law. New York ESRA supports electronic-signature/record validity but does not supply the same UETA automated-agent rule in Article 3.
07
Recognition does not allocate underlying liability
A court may confront recognition or confirmation after a merits process has occurred elsewhere. That enforcement question does not by itself determine who originally had delegated authority, who caused the loss, whether evidence was compromised, or how liability should be allocated.
08
Judicial enforcement cannot repair a broken delegation chain by itself
A later judgment or award can create a separate external instrument, but it does not retroactively prove that the machine actor originally possessed delegated authority. Attribution, agency, merits, forum, and enforcement remain distinct records.
09
Distributed systems can produce distributed responsibility
A harmful event can involve a principal, delegate, sub-delegate, developer, deployer, host, counterparty, data controller, compromised process, or external institution. Analysis should identify each causal and legal connection instead of selecting one automatic liability sink.
10
Engineering signals are evidence, not legal mental states
Reward functions, anomaly scores, confidence values, safety alarms, model outputs, or logs can be relevant evidence. They do not by themselves prove intent, knowledge, recklessness, negligence, causation, or guilt under the governing law.