New State Laws: Private Rights of Action for AI-Related Harms in Regulated Industries
In Canada and the UK, healthcare, insurance, and financial services executives face a growing risk as private rights of action for AI-related harms are incorporated into new state laws. This development raises litigation exposure beyond regulators and increases the cost of unexamined deployment.
These laws aim to hold organisations accountable when their AI systems cause harm by failing to meet expectations or adhering to industry standards. For regulated sectors, this means potential legal liability extends from regulators to individual customers, patients, or clients who suffer financial loss or injury as a direct result of AI errors.
Organisations buying or deploying AI in these industries now face three significant risks:
1. Capability risk: Can the technology do what was claimed? A vendor’s promise is no guarantee against failure when an organisation deploys it.
2. Governance risk: Can the decision be defended when boards, regulators, or courts ask questions about the technology’s implementation and management?
3. Liability risk: What does the organisation remain accountable for if its AI system causes harm or makes false claims?
To mitigate these risks, a prudent organisation should:
1. Review vendor claims against real operations and governance obligations by 2025.
2. Assess their current AI deployment against industry standards by end of Q2 2024.
Straven & Co examines AI decisions before they are acted on, delivering a plain verdict: proceed, proceed with conditions, or do not. By independent validation against the organisation’s people, operations, governance obligations, and legal exposure, Straven delivers trusted judgment before commitment.