Skip to content
Thoughts on the lia...
 
Notifications
Clear all

Thoughts on the liability angle? If the AI makes a bad call, who's at fault - us or the vendor?

3 Posts
3 Users
0 Reactions
1 Views
(@bluefox)
Estimable Member
Joined: 6 days ago
Posts: 54
Topic starter   [#18401]

This is the question that keeps me up after our last SOC upgrade! 😅 We're leaning on the AI for initial triage and escalation. It's fantastic 99% of the time.

But last week, it mis-prioritized a critical alert as low-risk. We caught it, but it got me thinking: our team overrode it, so it's on us. But what if it auto-remediates something in the future? The vendor's EULA is a mile of legalese basically saying "use at your own risk." Are we just accepting all liability by deploying it, or are there ways to share the risk? Curious how others are handling this with their legal teams.



   
Quote
(@auditor_abby)
Estimable Member
Joined: 4 months ago
Posts: 111
 

You're right to focus on the auto-remediation scenario. The human-in-the-loop catch you described is your current safety net, but it disappears the moment you enable automated actions. That's the liability cliff.

Your legal team needs to parse that EULA with one goal: identifying any indemnification clauses, however limited. In most I've seen, the vendor accepts zero responsibility for output or decisions. You're holding the bag.

We negotiated a carve-out with our last vendor for financial penalties tied to specific, documented failures of their model that bypassed their own stated accuracy thresholds. It was hard, and it only covered credits, not damages. But it established shared accountability in the contract, which is better than nothing.

Start by mapping every potential automated decision to a dollar value of impact. That's the only language that gets their attention.


Where is your SOC 2?


   
ReplyQuote
(@crusty_pipeline)
Estimable Member
Joined: 2 months ago
Posts: 142
 

Your catch on the override is the key detail. If your team has to review and approve every decision, you've effectively made the AI a fancy recommendation engine, and liability stays with your team's judgment call.

The minute you flip the switch for auto-remediation, you're accepting the vendor's "use at your own risk" clause as your operational reality. That legalese isn't there for their health, it's to insulate them. You're not just deploying a tool, you're adopting an unverified, autonomous actor with no legal accountability.

Ask your legal team to look for force majeure or gross negligence carve-outs. Sometimes you can get them to admit fault if their system fails to perform as explicitly documented, like missing a guaranteed uptime SLA. It's a tiny wedge, but it's something.



   
ReplyQuote