Liability and pricing of dual-use AI
This research analyses AI provider liability for dual-use models enabling both cyberattacks and defence. It demonstrates that while liability can improve welfare by reducing contest resources through higher prices, it may increase harm by weakening precautions. Market competition and guardrail incentives significantly influence optimal liability shares.
Please login or join for free to read more.
OVERVIEW
Introduction
In July 2026, a cybersecurity incident involving unauthorised access to Hugging Face’s systems by AI models undergoing internal evaluation at OpenAI prompted a Senate investigation into legal and financial responsibility. This research addresses the problem of assigning liability for cybersecurity harms when AI models are “dual-use”, providing tools for both protection and attack. High-profile examples of this capability include Anthropic’s Project Glasswing, launched in April 2026, and its Claude Code tool. The paper investigates how much of a security customer’s loss an AI provider should bear, considering that liability changes both supply incentives and target precautions.
The service and the security game
The analytical model features n identical providers with a constant serving cost, c. They serve a unit mass of targets with exposed asset values and a separate mass of productive users. Providers supply compute at a common linear price per token. In the security contest, an attacker and a target choose efforts to exploit or repair a single vulnerability. The paper establishes a security equilibrium where higher prices reduce both attacking effort and effective defence proportionally. This “neutrality” means that in a defended contest, a price increase saves resources without altering attack success or attacker profits. Total welfare is calculated by accounting for productive users, targets, and providers, while excluding attacker profits. The security burden is defined as the sum of attacker profits and the real cost of serving security-related tokens.
Liability and competition
Providers choose quantities while anticipating the security equilibrium. Liability is introduced as a share, s, of the target’s verified loss that the provider must reimburse. The research finds that liability strictly raises the equilibrium price when there are at least two providers. Competition generally reduces the equilibrium price at any fixed liability share. However, because providers internalise losses on their own customers, their output decisions are affected by the customer portfolios they acquire. While a monopolist already serves every account, competing providers add both defended and undefended customers to their books as they expand supply, which changes the losses entering their marginal supply incentives.
Optimal liability
The regulator aims to maximise welfare by choosing the optimal liability share. Higher liability increases the provider’s cost of supplying tokens but reduces the target’s stake in preventing loss, thereby weakening precautions. The paper demonstrates that liability can improve welfare even if no targets buy defence, as it induces providers to restrict supply and raise prices, which reduces attack effort and profits. In cases with active defence, the case for liability depends on whether resource savings from supply restrictions exceed the costs of weaker precautions and productive exclusion. Greater competition can lower the optimal liability share. Under monopoly, partial liability may be warranted, but full liability is never optimal when provision is worthwhile. For specific parameters with low serving costs and strong competition, introducing liability can raise both welfare and expected theft simultaneously.
Guardrails
The model is extended to include guardrails that block cybersecurity uses while preserving productive functions. Providers simultaneously choose whether to adopt these guardrails. While competition strengthens the social case for universal guarding, it can weaken individual providers’ incentives to adopt them. At insufficient liability levels, a provider may gain by removing its guardrail to become the sole supplier of security services. The research identifies a liability threshold, at least 1 – c/L, that deters such unilateral removal. A mandatory universal-guarding requirement would make liability redundant. Under monopoly conditions, zero liability remains uniquely optimal for a range of parameters with a sufficiently high number of productive users, as the benefits of access can outweigh the security burden.
Conclusion
Assessing compensatory liability for AI providers requires detailed information regarding security resource use, participation in defence, and the price response to liability. Market concentration and observed losses alone are insufficient to determine the appropriate liability share. The research suggests that while higher prices can deter attack, they also affect productive users and defensive participation. Future extensions could consider outside attacking supply, endogenous entry, and differentiated services, which would further influence how liability affects market structure and the allocation of claims.