AI Safety, Strategy, and Frameworks
No Superseding Actor: Notice, Causation, and Individual Criminal Liability for Frontier Model Deployment
- Travis Gilly, Real Safety AI Foundation
Publisher: Real Safety AI Foundation
Working draft. Not peer reviewed.
- Written
- September 2026
- Version
- v0.8
- Pages
- 26
Abstract
Applying settled doctrine to an unsettling technology is the ordinary work of the common law, not an innovation. Cardozo extended a manufacturer's duty past privity to the automobile in 1916, observing that the principle does not change but the things subject to it do; the dissent's answer, that any such change should come from the legislature and not the courts, lost. Hand held sixteen years later that a whole calling may lag in adopting an available device and never sets its own standard. This Article applies that ordinary work to autonomous model deployment. It argues that the accountability gap has been misdescribed. Federal law has punished as a principal anyone who willfully causes an offense through an innocent agent or instrumentality since 1948, so the model's want of a guilty mind resolves nothing for a purposeful actor; the surviving deficiency is a mens rea gap around reckless deployment, not a personhood gap. Causation compounds the developer's position rather than relieving it, because superseding cause excuses a defendant only when a responsible human agent intervenes, and in the July 2026 escape none did. Notice comes from the developers' own incident reports. Hamilton v. Beretta named the two things missing there, a direct link in the causal chain and a realistic position to prevent; both are present here. Two further claims follow. The responsibility-gap literature has treated liability as an instrument still to be designed, so its warning against legal solutionism reaches proposals rather than doctrine already in force. And financial incentive is a question of an element rather than of motive, because recklessness requires an unjustifiable risk and private gain is what makes a known risk to others unjustifiable. The defendant, finally, is not difficult to name: one developer's published governance instrument assigns final deployment authority to a single office and states that its safety function cannot delay a decision.
Keywords
- artificial intelligence
- corporate criminal liability
- superseding cause
- innocent instrumentality
- responsibility gap
- involuntary manslaughter
- industry custom
- flagrant organizational indifference
- agentic systems
- autonomous intrusion
- negligent entrustment
- deployment authority
Suggested citation
Gilly, Travis. "No Superseding Actor: Notice, Causation, and Individual Criminal Liability for Frontier Model Deployment." Real Safety AI Foundation Working Draft, September 2026. https://realsafetyai.org/research/no-superseding-actor/
References (49)
This paper cites its sources in footnotes. Each authority is listed once, where it is first cited, with its footnote number.
- Footnote 1.1 U.S.C. §1.
- Footnote 2.Andreas Matthias, The Responsibility Gap: Ascribing Responsibility for the Actions of Learning Automata, 6 Ethics & Info. Tech. 175 (2004) (control and prediction pass out of human hands before deployment)
- Footnote 2.Robert Sparrow, Killer Robots, 24 J. Applied Phil. 62 (2007)
- Footnote 2.Daniel W. Tigard, There Is No Techno-Responsibility Gap, 34 Phil. & Tech. 589 (2020).
- Footnote 3.MacPherson v. Buick Motor Co., 217 N.Y. 382, 391 (N.Y. 1916).
- Footnote 5.Thomas v. Winchester, 6 N.Y. 397 (N.Y. 1852), “not limited to poisons, explosives, and things of like nature.”
- Footnote 5.Winterbottom v. Wright, 152 Eng. Rep. 402 (Ex. 1842) (the privity rule the case displaced).
- Footnote 6.The T.J. Hooper, 60 F.2d 737, 740 (2d Cir. 1932) (Hand, J.).
- Footnote 9.18 U.S.C. §2(b)
- Footnote 10.Spurr v. United States, 174 U.S. 728 (1899) (bank officer who “purposely keeps himself in ignorance” acts willfully), discussed in Global-Tech Appliances, Inc. v. SEB S.A., 563 U.S. 754, 766 (2011).
- Footnote 12.Ann-Katrien Oimann, The Responsibility Gap and LAWS: A Critical Mapping of the Debate, 36 Phil. & Tech. 3 (2023).
- Footnote 15.Filippo Santoni de Sio & Giulio Mecacci, Four Responsibility Gaps with Artificial Intelligence: Why They Matter and How to Address Them, 34 Phil. & Tech. 1057 (2021).
- Footnote 17.Peter Königs, Artificial Intelligence and Responsibility Gaps: What Is the Problem?, 24 Ethics & Info. Tech. 36 (2022).
- Footnote 18.Simon Burton, Ibrahim Habli & Tom Lawton, Mind the Gaps: Assuring the Safety of Autonomous Systems from an Engineering, Ethical, and Legal Perspective, 279 Artificial Intelligence 103201 (2020)
- Footnote 18.Zoë Porter, Ibrahim Habli & Helen Monkhouse, The Moral Responsibility Gap and the Increasing Autonomy of Systems, in Computer Safety, Reliability, and Security 487 (2018).
- Footnote 19.Trystan S. Goetze, Mind the Gap: Autonomous Systems, the Responsibility Gap, and Moral Entanglement, in Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency 390 (2022).
- Footnote 23.Crumbley, 11 N.W.3d 576
- Footnote 24.Isaac Taylor, Collective Responsibility and Artificial Intelligence, 37 Phil. & Tech. 15 (2024).
- Footnote 25.United States v. Bank of New England, N.A., 821 F.2d 844, 856 (1st Cir. 1987) (corporations “compartmentalize knowledge, subdividing the elements of specific duties and operations into smaller components”), citing Riss & Co. v. United States, 262 F.2d 245 (8th Cir. 1958), Inland Freight Lines v. United States, 191 F.2d 313 (10th Cir. 1951), and Steere Tank Lines, Inc. v. United States, 330 F.2d 719 (5th Cir. 1964).
- Footnote 26.Anthropic, Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign (Nov. 2025), https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf (last visited Sept. 11, 2026).
- Footnote 34.OpenAI, OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation (July 21, 2026), https://openai.com/index/hugging-face-model-evaluation-security-incident/ (last visited Sept. 11, 2026)
- Footnote 34.Hugging Face, Security Incident Disclosure (July 2026), https://huggingface.co/blog/security-incident-july-2026 (last visited Sept. 11, 2026).
- Footnote 36.Anthropic, Investigating Three Real-World Incidents in Our Cybersecurity Evaluations (July 30, 2026), https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals (last visited Sept. 11, 2026).
- Footnote 37.Hjalmar Wijk, Ajeya Cotra & Ryan Greenblatt, Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident (Aug. 26, 2026) (assessment conducted on OpenAI premises; OpenAI retained redaction rights over non-public information and the assessors state that no redaction material to their conclusions was made).
- Footnote 40.OpenAI, OpenAI – Hugging Face Incident Technical Report (2026) [hereinafter Technical Report].
- Footnote 50.United States v. Bank of New England, N.A., 821 F.2d 844, 855–56 (1st Cir. 1987).
- Footnote 53.Global-Tech Appliances, Inc. v. SEB S.A., 563 U.S. 754, 769 (2011)
- Footnote 53.United States v. Jewell, 532 F.2d 697 (9th Cir. 1976) (en banc)
- Footnote 53.Model Penal Code §2.02(7).
- Footnote 54.Global-Tech states the contrast directly: the reckless defendant “merely knows of a substantial and unjustified risk,” Model Penal Code §2.02(2)(c)
- Footnote 59.People v. Crumbley, 346 Mich. App. 144, 11 N.W.3d 576 (2023).
- Footnote 60.People v. Derror, 475 Mich. 316 (2006), on a question concerning the knowledge element of Michigan’s operating-while-intoxicated statute
- Footnote 61.Crumbley, 346 Mich. App. 144.
- Footnote 64.People v. Schaefer, 473 Mich. 418 (2005) (separating factual from proximate causation), overruled in part on other grounds by People v. Derror, 475 Mich. 316 (2006)
- Footnote 64.People v. Feezel, 486 Mich. 184 (2010) (but-for causation)
- Footnote 64.People v. Otto, 18 N.W.3d 336 (Mich. Ct. App. 2023).
- Footnote 67.Hamilton v. Beretta U.S.A. Corp., 96 N.Y.2d 222, 234 (N.Y. 2001).
- Footnote 73.Purdy v. Public Administrator, 72 N.Y.2d 1 (N.Y. 1988)
- Footnote 73.Eiseman v. State, 70 N.Y.2d 175 (N.Y. 1987)
- Footnote 73.Lauer v. City of New York, 95 N.Y.2d 95 (N.Y. 2000) (no liability “however careless the conduct or foreseeable the harm” absent a duty running to the injured person).
- Footnote 77.compare Hymowitz v. Eli Lilly & Co., 73 N.Y.2d 487 (N.Y. 1989), with Healey v. Firestone Tire & Rubber Co., 87 N.Y.2d 596 (N.Y. 1996).
- Footnote 78.Protection of Lawful Commerce in Arms Act, 15 U.S.C. §§7901–7903.
- Footnote 89.N.Y. Cent. & Hudson River R.R. Co. v. United States, 212 U.S. 481, 495 (1909).
- Footnote 90.United States v. Cincotta, 689 F.2d 238 (1st Cir. 1982).
- Footnote 91.The Supreme Court later declined to extend Thurston’s formulation to the Fair Labor Standards Act, McLaughlin v. Richland Shoe Co., 486 U.S. 128 (1988)
- Footnote 102.United States v. Dotterweich, 320 U.S. 277, 284 (1943)
- Footnote 102.United States v. Park, 421 U.S. 658, 672–73 (1975).
- Footnote 103.OpenAI, Preparedness Framework (Version 2, Apr. 15, 2025), https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf (last visited Sept. 11, 2026).
- Footnote 104.OpenAI, OpenAI Safety Practices, https://openai.com/index/openai-safety-update/ (last visited Sept. 11, 2026).