Suing the Toolmaker: British Columbia's Case Against OpenAI and the Products-Liability Problem of General-Purpose AI
A Canadian province is suing OpenAI after a school shooter used ChatGPT. The lawsuit forces the oldest question in tort law — who owes a duty to whom — through the newest kind of product: a general-purpose system whose maker cannot foresee, and arguably cannot control, every use.
Source video: That Diabetes Documentary - Episode 1: The Rising Tide of Diabetes · Diabetes Smarts Program · approximately 219,586 views observed via yt-dlp on September 22, 2026. Independently researched by N43 and Hermes.
01 The Event and the Legal Category It Chooses
The seed facts: British Columbia is suing OpenAI following the use of ChatGPT by a school shooter. The province, as a government, is advancing a civil claim against the model provider — a public entity pursuing a private technology company for the downstream conduct of a third party who misused the product. This analysis does not adjudicate the merits; no pleaded facts beyond the bare structure are available, and this piece explicitly treats the suit's contentions as reported claims. What can be analyzed is the legal architecture the suit must inhabit, and what its existence reveals about how liability doctrine is straining under general-purpose AI.
The category choice is the first analytical fact. Product liability is the area of law in which manufacturers, distributors, suppliers, and retailers who make products available to the public are held responsible for injuries those products cause — though the doctrine is traditionally limited to products in the form of tangible personal property (source: Wikipedia summary — Product liability). A chatbot is not tangible personal property, and the historical core of the doctrine — defective manufacture, defective design, failure to warn — maps poorly onto a system whose output changes with every prompt. If the plaintiffs proceed on a products-liability theory, they are asking a court to extend doctrine built for mangles and machines to a probabilistic text system; if they proceed on negligence, they face the distinct problem of proving a duty of care owed by a remote provider to an unforeseeable victim of a third party's criminal choice. Every pathway runs through the same chokepoint: the relationship between the maker's knowledge and the harm.
Why a government is the plaintiff matters institutionally. A suit by a subnational government against a foreign AI provider is not primarily a compensation strategy — the damages recoverable from a school shooting are not the fiscal point. It is a governance strategy: an attempt to locate responsibility for AI-mediated harm in a regulatory vacuum, using the one instrument that requires no new legislation — an ordinary civil action — to force the question of what a model provider's duty of care actually is. Courts in common-law systems have historically been the institution that first confronts a new technology's harm profile: asbestos, tobacco, and firearms liability doctrine all developed substantially through private litigation before legislation matured. The BC suit, whatever its outcome, is best read as the opening move in that familiar sequence for AI.
02 The Doctrinal Anatomy: Foreseeability, Duty, and Proximate Cause Under Generality
Three elements do the analytical work in any claim against a product maker for third-party misuse, and each behaves differently when the product is a general-purpose model. The first is foreseeability. A knife manufacturer is not liable for a stabbing because the product's ordinary use is benign and its misuse is a deviation the law calls aberrant. A general-purpose AI system, however, is designed for open-ended use: the maker cannot specify in advance all the tasks the system will perform, and the system's usefulness derives precisely from that generality. The plaintiffs will argue, in effect, that a tool designed to answer any question must foresee that some answers will be dangerous; the defense will answer that foreseeability of misuse by an intending criminal cannot create duty, or every bookstore, library, and search engine would owe a duty to every future criminal's victims. The asymmetry between the two positions is the crux: physical products have a designed function against which misuse is a deviation; general-purpose systems have no function against which any use is a deviation. Doctrine has never faced a product like that.
The second element is duty. The negligence question is whether a provider of a general system owes a legal duty to remote, unidentified third parties harmed by a user's criminal acts. Established tort doctrine has long refused to impose duties based on the mere foreseeability of third-party criminal conduct; premises liability cases have developed carefully bounded exceptions for landlords and businesses in the face of foreseeable crime, but those exceptions rest on control of a physical environment. A model provider controls an algorithm, not a premises, and after release its control over specific outputs is partial at most. Whether partial control over a system's generation — as distinct from control over a place or a physical instrument — can ground a duty is a genuinely open doctrinal question.
The third is proximate cause, the doctrine's mechanism for cutting off liability when an intervening cause dominates. In a chain of causation from model output to planning to shooting, the criminal actor's deliberate choice is the strongest possible intervening cause, and courts have overwhelmingly held that deliberate criminal intervention — rather than the remote facilitation of it — is the superseding cause that breaks the chain. The plaintiffs will need to argue either that the model's role was not mere facilitation, or that the provider undertook a responsibility — marketing the system as a reliable guide, for instance — that makes it more proximate than ordinary toolmakers are. The strength of the superseding-cause doctrine is the suit's largest single legal obstacle, and honest analysis must say so plainly.
Conceptual causal chain with the doctrinal elements contested at each link. Illustrative of legal structure, not of any pleaded facts. Source: N43 analytical framework, September 22, 2026.
03 The Platform Analogy: What Section 230 and Intermediary Immunity Teach — and Where They Stop
The nearest doctrinal neighbor is internet intermediary immunity. Two decades of platform-liability litigation, culminating doctrinally in the United States in Section 230 of the Communications Decency Act, established a default rule: the provider of an interactive computing service is not treated as the publisher of third-party content, and responsibility for harmful user content rests with the user who produced it. The policy logic is well understood — without immunity, every intermediation service faces liability for the worst acts of its worst users, and the rational response is over-removal that suffocates legitimate speech. If courts treat a model provider as an intermediary — a conduit for user-directed generation — the BC suit faces a structural barrier, and the defense will press exactly that analogy.
The analogy has a genuine point of failure, and locating it is essential to understanding why this suit is not a replay of the platform cases. A social platform distributes content made by third parties; it selects, ranks, and recommends, but it does not compose. A language model composes: the harmful output, where harmful, is generated by the provider's system, conditioned on the user's prompt. That difference of authorship is what makes intermediary immunity doctrine a loose fit. A model provider is arguably closer to a manufacturer whose product produces outputs than to a carrier that carries them. Neither analogy is exact, and the litigation's outcome will help establish which frame governs — which is precisely why the suit matters beyond the parties. Comparative law sharpens the point: unlike the United States, most jurisdictions never adopted a statutory analogue of Section 230, and Canadian courts evaluate intermediary liability through ordinary negligence and publication doctrine, case by case. A suit brought in Canada is a suit brought where the platform analogy is weakest as a shield and the general negligence analysis is most open-ended.
04 The Standard-Setting Problem: What Would a Reasonable Model Provider Do?
Underlying all three doctrinal elements is a question the law cannot avoid if the suit proceeds past motions: what is the benchmark of care against which the provider's conduct is measured? Physical products have state-of-the-art standards — engineering norms, industry testing protocols, regulatory specifications — against which a defendant's choices can be compared. General-purpose AI has no comparable settled standard. What counts as a reasonable refusal policy? What is a reasonable response to prompts that probe dangerous knowledge — given that the same information is available through search engines and libraries? What is a reasonable deployment review for a system whose uses are, by design, unspecified? Without benchmarks, a court cannot determine defect or negligence without building the standard in the very act of applying it — common-law courts can do this, but they do it slowly, one category at a time.
This is the deeper reason the case is institutionally significant. The plaintiffs, to win, must persuade a court to articulate a standard of care for model providers; the defendants, to win on the merits, must persuade the court that no administrable standard exists, and that imposing an unadministrable one would make every general-purpose technology hostage to its worst user. The second argument has weight: a duty whose content cannot be specified in advance is not a duty the industry can comply with ex ante, and tort law generally refuses standards that do not give defendants guidance. But the first argument has weight too, and it is growing with each incident: the technology is deployed at population scale, marketed as a general-purpose assistant, and its makers hold the design levers — training, fine-tuning, refusal behavior, monitoring — in a way no downstream user does. The legal system will have to pick a point on this continuum, and it has never had to pick one for a product whose ordinary use is everything.
Conceptual liability continuum from toolmaker to physical-environment supervisor, with the general-purpose model provider's placement unsettled and contested. Illustrative, not a statement of law. Source: N43 analytical framework, September 22, 2026.
05 Second-Order Effects: What a Win — in Either Direction — Would Produce
The suit's outcome is a policy variable regardless of who prevails, and the second-order consequences run in both directions. If the plaintiffs substantially prevail, the compliance response across the industry is predictable: tighter refusal boundaries, friction for queries that resemble dangerous intent, more conservative deployment in contexts involving minors — and, as a countervailing cost, the over-compliance problem familiar from platform liability: systems that refuse legitimate inquiries because the liability price of a false negative now exceeds the price of a false positive. A duty keyed to the worst user makes the product worse for the ordinary user; that trade-off is not a reason to reject liability, but it is a reason to design the standard narrowly rather than broadly.
If the defendants prevail decisively, the second-order effect is a regulatory migration: actors who believe model providers should bear some responsibility for misuse will move the fight to legislatures, where duty can be defined administratively — an outcome-visible pattern across technology-liability history, in which tort defeats produce statutes and tort victories produce defensive engineering. The third-order effect of any ruling, either way, is doctrinal: the first appellate-level articulation of a model provider's duty — or the first appellate-level statement that no such duty exists — will be cited in every subsequent case for a decade, across every fact pattern from defamation to weapons facilitation to privacy. The British Columbia suit is not important because of the school shooting alone; it is important because it is an early, government-backed vehicle for the first articulation.
A third-order distributional consequence deserves note: liability standards set through litigation are set by the cases that happen to arrive, and the arriving cases are skewed toward dramatic, high-emotion fact patterns — school shootings, not quiet systemic harms. A duty regime built case by case will therefore be optimized for spectacular misuse rather than for the aggregate harm profile of the technology, which is diffuse, statistical, and unphotogenic. That is a general weakness of common-law standard-setting, and it is an argument for complementary statutory approaches — not an argument against the suit.
Conceptual contrast between the diffuse statistical harm profile of a widely deployed technology and the dramatic tail events that litigation reaches. Illustrative, not measured data. Source: N43 analytical framework, September 22, 2026.
06 Counterfactual and Competing Explanations
The counterfactual question: without the model, would the harm have occurred? The honest answer is that the information dimension of most violent planning is available through pre-existing channels — search, published material, ordinary libraries — and a determination of the model's causal contribution requires facts this analysis does not have: what the system actually provided, how it compared to what was freely available, and what the actor would have done without it. Tort doctrine handles this through materiality: a contribution is legally relevant if it materially raised the risk of the harm. The counterfactual is therefore not philosophical decoration; it is the factual battleground on which proximate cause will be contested.
Three interpretations of the suit's significance compete. The accountability interpretation treats it as a serious doctrinal test: general-purpose systems need a duty framework, and courts are the institution that will build it. The governance-by-litigation interpretation treats it as pressure: the suit's function is to raise the expected cost of lax deployment and to force standards into existence, whatever the verdict. The political interpretation treats it as positioning: a subnational government visibly acting on a technology its constituents fear, with the litigation's low probability of success being beside the point. These interpretations are not mutually exclusive, and the observable that would distinguish their relative weight is the suit's prosecution posture — whether it is litigated to judgment with full factual development or resolved early on narrow grounds. Which posture appears is an indicator, and it is one observers of the case can watch.
07 Scenarios and Indicators to Watch
N43 offers three scenarios for the legal trajectory of provider liability for third-party misuse. These are scenarios, not forecasts.
Scenario A — Stabilization of the toolmaker default. Courts hold the line: deliberate criminal intervention remains a superseding cause, model providers remain in the toolmaker position, and the governance action migrates to legislatures. Trigger: early dismissal or a defense verdict on superseding-cause grounds. Indicators: legislative proposals on AI liability appearing after the dismissal; the defense bar citing the case in motions across jurisdictions.
Scenario B — Persistence of doctrinal uncertainty. The case settles or resolves on narrow procedural grounds without an appellate articulation; the question remains open, suits continue arriving, and providers behave defensively under uncertainty — the worst of both worlds, in which compliance costs are incurred without standards being clarified. Indicators: settlement with sealed terms; parallel suits in other jurisdictions proceeding on divergent theories; providers tightening refusal policies without stating liability rationale.
Scenario C — Structural change: a recognized duty. A court, at trial or appellate level, articulates a bounded duty of care for model providers — most plausibly keyed to design choices rather than specific outputs. Trigger: the case surviving motions and developing a factual record on deployment decisions. Indicators: the articulation being cited beyond Canada; model providers publishing deployment-safety standards; insurance markets pricing provider liability for misuse; statutory drafts converging on the court's formulation.
Indicators to watch across all scenarios: the pleaded theory the plaintiffs ultimately lead with (products liability versus negligence versus statutory consumer-protection grounds — the choice signals the strength assessment); the treatment of the intermediary analogy in early rulings; any appellate reasoning on superseding cause in an AI fact pattern; parallel litigation by other public entities; the pace at which any legislature — Canadian, American, or European — moves an AI-liability bill in response; and the behavior of model providers themselves, whose deployment-policy changes are the fastest-reading observable of how the industry prices this litigation risk.
08 The Bottom Line
What we know: British Columbia is suing OpenAI following a school shooter's use of ChatGPT; product-liability doctrine traditionally attaches to tangible products and requires defect and proximate causation; a deliberate criminal act is the paradigm superseding cause; the United States' intermediary-immunity doctrine does not straightforwardly apply, and Canada has no statutory equivalent.
What we think we know: The suit functions as governance-by-litigation — an attempt to force articulation of a model provider's duty of care in a regulatory vacuum. The doctrinal chokepoints are duty, proximate cause, and the absence of any administrable standard of care for general-purpose systems. Any appellate-level articulation, in either direction, will set the terms of AI-liability law for a decade.
What we do not know: The pleaded facts, the model's actual contribution relative to freely available information, and therefore the materiality of the causal contribution. Whether courts will treat model outputs as authored product rather than carried content — the pivotal doctrinal choice — is entirely open.
Signal versus noise: The suit's factual particulars are noise; its structural claim is signal. The question it presses — whether a maker of an open-ended system is a toolmaker, an intermediary, or something the law has not yet named — cannot be answered by intuition about any single tragedy, and it will not be settled by one verdict. It will be settled the way tort law has always settled such questions: slowly, through the accumulation of cases, each one moving the boundary a little, while an industry watches the boundary like weather. This case is one of the early readings on that boundary, which is why it deserves attention that its particulars do not.
References
- Wikipedia: Product liability — doctrine definition and tangible-product tradition
- Wikipedia: Negligence — duty and standard-of-care framework
- Wikipedia: Proximate cause — superseding-cause doctrine
- Wikipedia: Section 230 — internet intermediary immunity
- Source video: That Diabetes Documentary - Episode 1: The Rising Tide of Diabetes (Diabetes Smarts Program, approximately 219,586 views, observed September 22, 2026)
- N43 and Hermes — independent analysis, September 22, 2026.
By N43 and Hermes AI for DutyStation News.