For most of the short history of generative AI in legal practice, the liability risk has lived in text: the fabricated citation, the invented case, the hallucinated statute. The cases that set the benchmark — Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023) and Park v. Kim, 91 F.4th 610 (2d Cir. 2024) — involved AI-generated documents filed as if they were the product of human research. That problem is real and ongoing. But it is no longer the frontier.
The cases landing now raise a harder question: what happens when AI does not just generate a document but takes a real-world action — logs into an account, executes a transaction, files a motion, advises a litigant to fire her lawyer and reopen a settled case? Two federal cases from 2025 and 2026 mark the boundary. Together they reveal a structural liability gap between developer, deployer, and user — space that existing doctrine does not cleanly fill — and a category of dispute that will grow quickly as agentic AI embeds itself in commercial and legal practice.
§ 01 · What an AI agent does
A chatbot takes a prompt and returns text. An AI agent is different in kind. It uses that text as the basis for a sequence of real-world actions, cycling through a loop of perception, planning, and execution until a goal is met. Given access to a web browser, the agent visits sites, logs into accounts, and completes transactions. Given access to document systems, it drafts, searches, and files. Given access to a user's legal situation and a large language model trained on legal text, it evaluates counsel's advice, draws conclusions, and prepares filings — all without a human reviewing each step. The capability that makes agents commercially attractive is precisely the capability that creates exposure when any of those steps touches a system the agent was not supposed to reach, produces advice that drives a damaging course of action, or causes harm to a third party who never agreed to anything.
§ 02 · The authorization split
Amazon.com Services LLC v. Perplexity AI, Inc., No. 3:25-cv-09514-MMC (N.D. Cal., filed Nov. 4, 2025), is the leading federal case on the platform-authorization question. Perplexity's Comet application is an AI agent built to act on behalf of users: it logs into Amazon accounts, browses products, compares prices, and executes purchases without the user clicking through the steps manually. Amazon argued that this constituted unauthorized access under the federal Computer Fraud and Abuse Act and California's Computer Data Access and Fraud Act.
Perplexity's core defense was direct: the user authorized Comet to act on the user's behalf, so Comet's access was authorized. Judge Maxine Chesney rejected that framing when she granted Amazon a preliminary injunction on March 9, 2026. The court found strong evidence of a violation, holding that Comet had accessed Amazon's systems "with the Amazon user's permission, but without authorization by Amazon." User authorization does not travel to the platform the agent operates on. The Ninth Circuit heard oral argument on June 11, 2026, and has not yet ruled — making this the live question for every commercial AI agent deployed across third-party platforms.
§ 03 · When the agent advises
Nippon Life Insurance Company of America v. OpenAI, No. 1:26-cv-02448 (N.D. Ill., filed Mar. 4, 2026), shows what happens when the agent's output is advice, and the advice causes downstream harm. The case arose from a disability benefits matter resolved by settlement. The claimant, Graciela Dela Torre, uploaded her attorney's correspondence into ChatGPT and asked the system to evaluate what she had been told. ChatGPT reportedly responded that she was being "gaslighted" and suggested the settlement may not have served her interests. She fired her lawyers and began using ChatGPT to research how to vacate the settlement and reopen the lawsuit.
ChatGPT allegedly helped her draft and file 44 post-settlement motions, subpoenas, and related documents, several containing fabricated case citations. Nippon, which incurred approximately $300,000 in attorneys' fees responding to those filings, sued OpenAI for the unlicensed practice of law under Illinois statute (705 ILCS 205/1), tortious interference with the settlement contract, and aiding an abuse of process. OpenAI moved to dismiss, arguing that ChatGPT is "not a 'person,' but a tool that relies on statistics to predict the most appropriate sequence of words" and is "incapable of practicing law within the meaning of the statute." The structural question — does the injury belong to the developer, the deployer, or the user? — is the question these disputes will force the legal system to answer.
User authorization does not travel to the platform the agent operates on. The "AI did it" defense is gone in California. What neither doctrine resolves is how much of the liability belongs to the model developer, the deployer, and the user.
§ 04 · The legislative response
California filled one piece of this gap with AB 316, signed October 13, 2025, effective January 1, 2026. The statute bars defendants who "developed, modified, or used" an AI system from asserting as a defense that the AI "autonomously caused" the harm. It covers the full supply chain: the foundation-model developer, the company that fine-tunes the model, the integrator that builds on it, and the enterprise that deploys it. The "AI did it" defense is gone in California.
What AB 316 does not do is allocate responsibility among the parties in the chain. It removes one argument without resolving how much of the liability belongs to the developer whose training produced a model willing to advise a pro se litigant, how much to the deployer that put the system in front of her, and how much to the user who prompted it. That allocation question — technically contested at the level of model architecture, training choices, and deployment configuration — is precisely what existing litigation frameworks handle least efficiently.
§ 05 · Why these disputes need a technically fluent neutral
The factual questions underneath these disputes are technical: what did the agent do on Amazon's servers? What instructions did it receive, from what configuration, and from what user input? What was ChatGPT's output when Dela Torre asked about her settlement — verbatim — and what training and deployment choices made that output likely? Those questions live in access logs, model configurations, system prompts, and training records that most counsel and most courts are not equipped to evaluate unaided.
The JAMS Artificial Intelligence Disputes Clause and Rules, effective June 14, 2024, already provide a framework for this class of case — including mechanisms for accessing AI systems and training data in secured expert-only environments, appointing technically fluent neutral experts, and selecting arbitrators with demonstrated AI competence. A neutral who can read the access logs and the Computer Fraud and Abuse Act simultaneously resolves the platform-authorization question more efficiently than a generalist jury. A neutral who understands what a large language model produces from a given prompt, and what training and deployment choices shaped that output, is better positioned to apportion liability than competing expert submissions before a court that has never examined an AI model's internals. These disputes are complicated not because the law is complex alone, but because the facts require a second language.
AI agents will keep acting. The doctrine governing what they can do — and who pays when they act wrongly — is still forming. Parties most exposed are those who have not chosen their forum before the incident. Build the arbitration or mediation clause before the agent is deployed. Once the agent has acted and the dispute has followed, the time to design the process has already passed.
Draws on Amazon.com Services LLC v. Perplexity AI, Inc., No. 3:25-cv-09514-MMC (N.D. Cal. 2025); Nippon Life Insurance Company of America v. OpenAI, No. 1:26-cv-02448 (N.D. Ill. 2026); Jones Day, "Authorized by the User, Blocked by the Platform: Testing the Legal Limits of AI Agents" (May 2026); Baker Botts, "California Eliminates the Autonomous AI Defense: What AB 316 Means for AI Deployers" (2025); Norton Rose Fulbright, "AI in Litigation Series: Complaint Accuses OpenAI of Practicing Law Without a License" (Apr. 2026); and the JAMS Artificial Intelligence Disputes Clause and Rules (effective June 14, 2024).