Scott Winters was fifty-five and out of patience with doctors when he started typing his symptoms into ChatGPT in June 2024. He had been diagnosed with small intestinal bacterial overgrowth and with chronic prostatitis, and he felt the medical system had stopped listening. Over the following year, according to the complaint he later filed, the model kept telling him to rest, to stay off the leg, to remain in the recliner where the clots would eventually form.
On the morning of 13 July 2025 he described groin tenderness and odd twinges running through his body, and asked whether he should go to the hospital. He was told the tenderness was very likely another minor piece of the long story of his condition, and not something dangerous. Hours later he called 911 with palpitations and shortness of breath. In intensive care, doctors found massive clots in both lungs. One of his own physicians attributed them to the prolonged immobility.
In late July 2026 Winters sued in San Francisco County Superior Court, naming OpenAI and naming Sam Altman personally. He wants damages, and he wants an injunction pausing ChatGPT Health until an independent safety evaluation is done.
The next day, OpenAI launched ChatGPT Health to every US user over eighteen. The company says more than 300 million people a week already bring health questions to ChatGPT, up from 230 million. The feature connects Apple Health, supported US hospital systems, One Medical and Function Health, and OpenAI says it was evaluated against a benchmark called HealthBench Professional, with hundreds of physicians writing the rubrics.
Look at what the complaint is and is not. It is not a defamation claim, and it does not ask a court to weigh what a platform hosted for somebody else. It alleges negligence and the unauthorized practice of medicine, the claims you bring about a thing that hurt someone.
That distinction carries more weight than any AI bill drafted anywhere this year. Every liability shield the internet was built on assumes publishing. Section 230 immunises the hosting of someone else’s speech. The First Amendment protects an utterance with a human intent behind it. Defamation requires a false statement of fact about a person. Three shields, one shape: they all protect words.
Product liability asks nothing about words. It asks whether the design was defective, whether the warning was adequate, whether the harm was foreseeable, and whether a safer design was available at the time. It does not ask what anyone intended. It has no immunity clause. And it reaches every party in the chain of distribution, not only the maker.
A federal judge in Florida has already crossed that line. Ruling in May 2025 on Character Technologies’ motion to dismiss in the Garcia case, Judge Anne Conway declined to treat chatbot output as protected speech, reasoning that it lacked the human expressive intent the First Amendment requires, and allowed design-defect claims to proceed against the chatbot as a product. That case then settled as part of a package of resolutions across four states. The doctrine came off the docket before an appellate court could look at it.
So how did OpenAI answer Winters? Not with the First Amendment. A company spokesperson said ChatGPT was never designed to replace a healthcare provider, and that its terms of service warn users not to rely on it as a sole source of medical guidance.
Parse that defence. It rests entirely on the adequacy of a warning. Failure to warn is one of the three classic defect theories in product liability, and arguing about the sufficiency of your warning concedes both that there was something to warn about and that you were obliged to do it. The company answered in the register of the law it says does not apply. It made the same move in its November 2025 answer in the Raine wrongful-death case, arguing the harm flowed from misuse of the product in violation of its terms of use.
The insurance market got there first. On 1 January 2026, ISO issued three endorsements excluding generative-AI bodily injury and property damage from commercial general liability cover. Those forms sit under roughly 82 per cent of US commercial liability insurance. Chubb, Travelers and Berkshire Hathaway have regulatory approval to attach AI exclusions to general liability, directors-and-officers and errors-and-omissions policies. Insurers do not write exclusions for speech risk. They write them for products.
Which leaves the field in an odd position. No appellate court in the United States has decided whether a generated answer is a product. But the underwriters have priced it, the defence bar has adopted its vocabulary, and the largest defendant in the industry has now argued its most serious personal-injury case in exactly those terms. The characterisation was never waiting on a ruling. It has been settling into place for eighteen months on the paperwork, while everyone watched Congress not pass a bill.
The Deep Dive
Erling Larsen was driving a Corvair in 1967 when a head-on impact drove the steering column back into his head. General Motors argued it owed no duty to design a car for a collision, because a collision is not what a car is for. In 1968 the Eighth Circuit rejected that on a single premise: collisions are statistically foreseeable, so a manufacturer must take reasonable care to limit the injury when one happens. Five years earlier the California Supreme Court had made strict liability the rule for defective products in Greenman v. Yuba Power Products, and Congress had passed the National Traffic and Motor Vehicle Safety Act in 1966.
Tobacco took far longer and shows the shape more clearly. Two entire waves of litigation produced no payment to any plaintiff. Rose Cipollone’s family won $400,000 in 1988 and lost it on appeal. Carter v. Brown & Williamson, in 1996, was the first cigarette lung-cancer verdict to survive final appeal, for $750,000. Two years later came the Master Settlement Agreement at a minimum of $206bn. What changed between 1988 and 1996 was not the law of negligence but the arrival of the industry’s own internal documents.
That is the sequence each of these industries followed, in order. Conceal the internal risk assessment. Fight discovery for a generation. Lose once the documents surface. Then accept a federal regulator, and discover the regulator is also armour: an approved FDA label preempts most state failure-to-warn claims, premarket approval preempts device claims, federal motor-vehicle standards become a defence. Industries pay for their rulebook in verdicts, and it is worth what it cost.
Generative AI has run that sequence in reverse, and did it voluntarily. Start with the record. Tobacco’s plaintiffs needed four decades, a whistleblower and a document depository to prove the industry had measured the risk. The labs simply publish: system cards, model cards, red-team findings, and for this product an evaluation against HealthBench Professional with hundreds of physicians writing the rubrics. Foreseeability took tobacco plaintiffs thirty years to establish. Here it sits in the release notes.
Then the harder one. A design-defect claim under the Restatement Third generally requires the plaintiff to identify a reasonable alternative design that was feasible at the time, and that requirement kills most such claims. Larsen’s lawyers had to argue about a steering column against a manufacturer controlling the engineering record. A model developer publishes a comparable safety number every time it ships. If a later configuration scores better on the same rubric, feasibility has been proven by the defendant, dated to the day, in a document written for marketing. Every upgrade timestamps the version it replaced.
And no shield is coming to balance it. The AI LEAD Act, S.2937, introduced by Senators Durbin and Hawley in September 2025, would classify AI systems as products and create a federal products-liability cause of action. It has sat in the Judiciary Committee ever since. Note its direction: a sword, not a shield. Europe moves the same way from the other side, since the revised Product Liability Directive brings software including AI systems inside the definition of a product, to be transposed by member states in December 2026. A single global product cannot be speech in California and a product in Dublin for very long.
The strongest argument against all of this is not the First Amendment. It is that the analogy fails at the level of the object, and it fails twice, in opposite directions.
Pharmaceutical manufacturers are protected less by preemption than by the learned intermediary doctrine, under which the maker warns the prescribing physician whose independent judgement then stands between the warning and the patient. It breaks the causal chain, and it has ended more failure-to-warn claims than any statute. A chatbot has no intermediary. The product is the intermediary, addressing the patient directly, which is why OpenAI’s answer reached for the user’s own acceptance of the terms of use. The defence is trying to build a learned intermediary out of the plaintiff.
Now the direction that cuts the other way, and it is the serious one. Every prior product-liability regime rests on identical units. Two Corvairs share a steering column. Two tablets share a molecule. Two identical prompts do not have to produce the same answer, and a manufacturing-defect theory needs a deviation from a specification that does not exist here. Winters cannot show his output departed from the intended one, because there is no intended one.
That does not defeat the case. It narrows the case to design defect and failure to warn, and it changes what the litigation is about. If no individual answer can be defective, the thing on trial is the distribution: how often, across thousands of comparable queries, the model told a user reporting those symptoms to rest. Which makes the decisive fight not Winters’s transcript but OpenAI’s aggregate output logs, and that is not where the reporting has gone.
So the parallel breaks in a direction neither side has priced. Tobacco and automobiles were tried on units. This will be tried on rates. A defendant able to show a low enough base rate on a rubric it published has a real defence, possibly a complete one. A defendant that published the rubric and cannot produce the rate has handed the plaintiff the question while keeping the answer, which is the posture courts punish hardest in discovery.
That is also where the money moves first, because underwriters do not wait for appellate courts. They wait for exposure they cannot model, and then they write it out. ISO’s three endorsements landed on 1 January 2026, before any US appellate court had said a word on the question, and with Verisk’s forms sitting under roughly 82 per cent of US commercial liability cover, the exclusion is now the default text of the market. What has grown in its place is thin: Armilla writing as a coverholder under Chaucer syndicates 1084 and 1176 at Lloyd’s, Testudo launched as a managing general agent in January 2026, Google Cloud’s affirmative endorsements alongside Beazley, Chubb and Munich Re. Against an industry committing hundreds of billions in capital expenditure, that is a rounding error of capacity.
And the exposure does not stop at the developer, because product liability never has. ChatGPT Health connects Apple Health, supported hospital systems, One Medical and Function Health. Under a publishing frame none of those relationships create exposure, because a distributor of someone else’s speech is protected. Under a product frame each is a link in a chain of distribution, and the general counsel at the far end have all read Garcia.
Which brings the argument to a demurrer hearing in a San Francisco courtroom, probably this autumn. Two courts have already declined to dismiss claims framed this way: Judge Conway in Garcia, and the Northern District of California in the social-media adolescent-addiction litigation, which let design-defect claims through function by function. California is also where Greenman was decided, a jurisdiction with permissive product-liability instincts and a forgiving pleading standard.
If you advise a lab, a health system or an insurer, plan for the world where the design-defect and failure-to-warn counts survive the demurrer, the claim against Altman personally is struck, the injunction is denied as far too blunt a remedy, and the case walks into discovery with the product characterisation intact in a second courtroom. That path carries fifty-six per cent, because each element is independently the likeliest outcome for reasons that do not depend on the others. Personal liability for a chief executive on a negligent-design theory rarely survives a pleading challenge, injunctions shutting a live consumer feature are extraordinary relief, and both courts to examine this framing let it through.
The alternative to prepare for is subtler, and would be misread everywhere as a defeat for the plaintiff. The court sustains the demurrer on the product question, holding that a generated answer is not tangible personal property within California’s definition, while letting an ordinary negligence claim proceed. Nineteen per cent sits here. It would be reported as a win for OpenAI and it would be nothing of the sort, because negligence without strict liability still puts the design in front of a jury; it merely makes the plaintiff prove what strict liability would have presumed. What it does change is the insurance question, since a negligence claim fits inside cover a products claim increasingly does not.
Then there is the route Character Technologies took. OpenAI resolves this and the related personal-injury claims privately before any ruling on the product question, buying the doctrine off the docket exactly as the Garcia settlement did, at a price trivial against the company’s capital expenditure. Anthropic’s authors’ settlement, approved on 20 July 2026 at $1.5bn across roughly 500,000 works, is the template: it resolved how the books were obtained and left the fair-use question standing. Seventeen per cent, rising each month the Raine docket advances, because a defendant facing several of these at once has more reason to clear them together than to win one loudly.
The outcome that would reset the field is the one where the complaint fails at the pleadings altogether: no duty, no causation, the terms of use doing the work OpenAI’s spokesperson says they do. Eight per cent is below what four blind guesses would allocate, and it belongs there for a reason. Winters pleads a treating physician’s causal attribution of the clots to immobility, a demurrer tests the pleading and not the evidence, and a court dismissing on causation here would be resolving a factual dispute it is not yet permitted to resolve.
Two developments would move these numbers. A published appellate decision anywhere in the United States holding that model output is not a product would collapse the first two paths into each other and lift the fourth sharply. And if OpenAI’s formal answer pleads the First Amendment after all, this read needs revisiting, because it would mean the company still believes it has a speech defence worth keeping.
The signals are all small and all textual. Sometime this autumn a judge in San Francisco rules on the demurrer, and the two or three sentences of that order addressing whether a generated answer is a product will matter more than any AI legislation drafted anywhere this year. In December the European transposition deadline arrives and software becomes a product across the single market by operation of law. On 1 January the liability forms renew, and the only live question is whether the AI exclusions stay optional. And underneath the chat box, in grey six-point type, sits the sentence that tells you what the industry believes.
Right now it says the model can make mistakes. A warning label does not say that. A warning label names the injury and tells you what to do instead, because a warning that vague has never once been held adequate by an American court. The day that line changes on a health screen to name a symptom and an emergency room, the industry will have conceded in six-point type what it spent two years declining to concede in a brief. It will be the size of a fingernail and it will be the most expensive sentence in the product.
Sources:
Courthouse News Service, “Man sues OpenAI over ‘dangerous’ medical advice from ChatGPT,” 23 July 2026.
CBS News, “ChatGPT’s medical advice nearly killed a Florida man, lawsuit against OpenAI claims,” 23 July 2026.
Engadget, “OpenAI sued over ChatGPT health advice that almost killed a pastor,” 23 July 2026.
Quartz, “A Florida pastor is suing OpenAI over ChatGPT health advice that nearly killed him,” 23 July 2026.
MobiHealthNews, “Former pastor sues OpenAI over ChatGPT health advice,” July 2026.
OpenAI, “Introducing ChatGPT Health,” 23 July 2026.
TechCrunch, “OpenAI makes ChatGPT Health available to all U.S. users,” 23 July 2026.
SiliconANGLE, “OpenAI launches Health in ChatGPT a day after lawsuit seeks to block it,” 23 July 2026.
Courthouse News Service, “Florida judge rules AI chatbots not protected by First Amendment,” May 2025, on Garcia v. Character Technologies, Judge Anne Conway, M.D. Fla.
Transparency Coalition, “In early ruling, federal judge defines Character.AI chatbot as product, not speech,” 2025.
Reed Smith, “Courts Redefining Software As Product Generates New Risks,” on In re Social Media Adolescent Addiction Personal Injury Products Liability Litigation, N.D. Cal. 2023.
K&L Gates, “AI Product Liability: The Next Wave of Litigation,” 27 March 2026.
Raine v. OpenAI, case CGC-25-628528, San Francisco County Superior Court, complaint filed August 2025, amended October 2025, OpenAI answer November 2025.
Congress.gov, S.2937, 119th Congress, “AI LEAD Act,” introduced 29 September 2025, referred to the Committee on the Judiciary.
United States Senate Committee on the Judiciary, “Durbin, Hawley Introduce Bill Allowing Victims To Sue AI Companies,” 29 September 2025.
Directive (EU) 2024/2853 on liability for defective products, member state transposition deadline December 2026.
Insurance Services Office endorsements CG 40 47, CG 40 48 and CG 35 08, generative AI exclusions for commercial general liability, effective 1 January 2026.
Verisk, share of US commercial liability insurance written on ISO forms, approximately 82 per cent.
Agent Insured, “The Lloyd’s Market and AI Liability: Capacity, Coverholders, and the London Market’s 2026 Posture,” 2026, on Chaucer Syndicates 1084 and 1176 and Armilla Insurance Services.
Testudo, “AI Insurance Market Update Q1 2026,” on its January 2026 launch as a managing general agent.
TechCrunch, “Anthropic’s landmark $1.5B copyright settlement is approved,” 20 July 2026.
The Washington Post, “Judge approves a $1.5B Anthropic settlement over pirated books used to train the Claude chatbot,” 21 July 2026.
Larsen v. General Motors Corporation, 391 F.2d 495 (8th Cir. 1968).
Greenman v. Yuba Power Products, Inc., 59 Cal. 2d 57 (1963).
National Traffic and Motor Vehicle Safety Act of 1966.
Nolo, “History of Tobacco Lawsuits: Cigarette Litigation, the Master Settlement, and More,” on Cipollone v. Liggett Group and Carter v. Brown & Williamson Tobacco Corporation.
Library of Congress Research Guides, “Tobacco Settlement,” on the November 1998 Master Settlement Agreement and the $206bn minimum.
Disclaimer: This report is published by Scenarica Intelligence for informational purposes only. It does not constitute investment advice, a solicitation to buy or sell any financial instrument, or a recommendation regarding any particular investment strategy. Scenarica Intelligence is not a registered investment adviser or broker-dealer. All scenario probabilities and assessments represent the analytical judgment of Scenarica Intelligence and are subject to change without notice. Past performance of any asset or strategy discussed does not guarantee future results. Readers should conduct their own due diligence and consult with qualified financial advisers before making investment decisions.
Scenarica Premium: The full Scenarica suite includes Geopolitics, Economy, Bitcoin, AI, and Sunday Edition.
Scenarica Intelligence
We don’t predict the future. We price it.








