Who Is Responsible When AI Gets It Wrong at Work? Not the Vendor
There is a public database of court cases in which someone filed work containing citations that artificial intelligence invented. In June 2026 it passed 1,500 cases, and it was growing by roughly eight a day.
These are lawyers. Checking citations is not an incidental part of that job, it is the job. If it happens at that rate to people whose profession is verification, it is worth knowing what happened to them afterwards, because the pattern is not the one most managers expect.
One thing up front: this is not legal advice, and it describes the US picture. Ask your own counsel about your own situation.
The mistake is rarely what gets punished
Read through the 2026 sanctions and a shape emerges. Two cases from April make it clearest, because the underlying error is nearly identical.
In one, a lawyer filed nonexistent citations and fabricated quotations, then explained candidly what had happened: they had believed the tool had protection against making things up. The court accepted the explanation and imposed no sanction at all.
In the other, an assistant US attorney filed fabricated quotations and initially concealed that AI had been used. The result was a public reprimand, and they resigned after the hearing.
The rest of the year rhymes with that. Attorneys who refused to answer the court’s questions and challenged the order drew $15,000 each in punitive Penalties a court imposes directly on the person or firm for how they behaved in the case, separate from who wins or loses. They can be money, a public reprimand, removal from the case, or referral to a disciplinary body. The point worth noticing is that they land on the individual professional, not on the client who hired them. , plus the other side’s fees, double costs, and a disciplinary referral. An attorney who was evasive and misleading about whether AI had been used drew a smaller financial penalty and a much longer paper trail.
There is an honest exception, and it matters. In one appeal the court noted the lawyer’s candor and clean record, and still called the conduct inexcusable: the case was reassigned and all compensation denied. Being open is not a formula that makes it go away.
But the direction is unmistakable. The error is survivable. Concealing it generally is not.
You cannot buy your way out of the responsibility
The second thing managers get wrong is assuming the vendor absorbs the risk. It is an intuitive assumption. You bought a product, the product malfunctioned, surely that is the manufacturer’s problem.
Where US law has been most explicit, it points the other way. Writing about AI in employment decisions specifically, the employment team at K&L Gates puts it in one line: “Outsourcing doesn’t shift responsibility. Employers remain fully liable for bias or discrimination introduced by third-party systems.” Litigation has begun to test whether vendors can also be liable directly, but that is a separate question from whether the employer stops being liable, and so far the answer to the second is no.
That is a narrower statement than “you are responsible for everything AI does at your company.” It is about employment decisions, where the obligations are written down. But the underlying logic travels, and it is the same logic that governs the rest of your team’s output: work produced on your behalf, by someone you employ, using a tool you provided, is your organization’s work.
Which is really an instance of something older than AI. The long-standing principle that an employer is answerable for what employees do in the course of their work. It is why a firm carries insurance for its staff rather than asking each person to insure themselves. AI does not create a new category here: an employee using a tool badly is still an employee doing their job, and the tool being clever does not move the responsibility onto it. is not a new doctrine invented for chatbots.
What follows for a manager who is not a lawyer
Four things, none of which require a legal budget.
- Treat AI output as your team’s work product, whoever typed it. The question “did a person or a model write this?” has no bearing on who answers for it.
- Name who checks what, before it goes out. Not “everyone should check their work,” which is a feeling. A named person and a named step, scaled to what it costs to be wrong. How to Check AI’s Work covers what the check has to catch, which is not the error most people brace for.
- Make disclosure the cheap option. This is the direct managerial lesson from the sanctions. If admitting a bad AI output costs someone more than quietly hoping, you have built the concealment problem into your own team. The half-hour review in AI Mistakes at Work is designed to make that admission survivable.
- Read your vendor terms for what they actually promise. They are written to allocate risk to the customer, and the indemnities that exist tend to be narrow and conditional. Assume the contract protects the vendor, because that is what it is for.
Ultimately, there needs to be a human in the loop. Treat AI as a new junior employee. You wouldn’t give a junior employee, new to the company, the ability to publish work to production (whether it’s reports, analysis, or code), without reviewing and checking their output for accuracy. Treat AI the same way: trust but verify its output always.
Then write the answer down somewhere people will find it. A rule nobody can locate is not a rule, which is the whole argument of Write a One-Page AI Policy Your Team Will Actually Follow and the toolkit’s ground rules guide.
The takeaway
Courts have spent 2026 answering the question this post asks, over and over, in the one profession where checking sources is the entire job. The answers have been consistent: the person who filed it is responsible, the tool is not a defense, and what changes the outcome is what you do in the hour after you find out.
Decide now who answers for AI-assisted work on your team, and make owning up to a bad one cheap. Both of those are free today and expensive to arrange retrospectively, which is the position everyone in that database was in.
Sources: the 2026 sanctions cases, including the contrast between the candidly explained filing that drew no sanction and the concealed one that drew a public reprimand, are drawn from Norton Rose Fulbright’s tracker AI in litigation: Update on Gen AI sanctions in 2026 (opens in a new tab). The case count is from the AI Hallucination Cases database (opens in a new tab) maintained by Damien Charlotin at HEC Paris; the figure of just over 1,500 in June 2026 and the roughly eight-a-day growth rate come from reporting on that database rather than from the database itself, which I could not reach directly, so treat the exact number as approximate and the direction as the point. It also counts only cases where a court explicitly found hallucinated material, so it undercounts. The employer-liability quotation is from Navigating the AI Employment Landscape in 2026 (opens in a new tab) (K&L Gates, 3 February 2026), and applies specifically to employment decisions. This post is not legal advice, the picture is US-focused, and the extension from employment decisions to work product generally is my reading rather than a stated legal holding.
Related: AI Mistakes at Work: Run a 30-Minute Post-Mortem, Not a Witch Hunt is the procedure for the hour after you find out. Write a One-Page AI Policy Your Team Will Actually Follow is where the answer to “who is responsible” should be written down.