The inaugural Workshop on Law-Following AI (LFAI), hosted by the Institute for Law & AI at the University of Cambridge from August 6–8, 2025 with support from the Leverhulme Centre for the Future of Intelligence and the UK's Advanced Research & Innovation Agency, convened more than forty scholars from law, computer science, and related disciplines to advance the emerging research agenda around LFAI: a concept denoting agentic AI systems designed to refuse illegal orders and illegal means, the corresponding policy proposal to mandate such design in certain deployment contexts, and the interdisciplinary field of inquiry that supports both. Rather than recording consensus, these proceedings synthesize key themes from the workshop's presentations and discussions, including the promises and limits of liability (particularly for governmental AI agents), the state and nuances of automated legal reasoning and evaluation, risks posed by automated compliance and "perfect enforcement," the appropriate standard of care for AI agents, and the interplay between AI agents and their principals, including fiduciary framings. The report is intended to extend the workshop's conversations to a broader audience and catalyze further scholarship on LFAI's design, evaluation, and governance.
A casual observer would be excused for thinking that corporate crimes are generally victimless. Even an informed observer would be hard pressed to articulate how, if at all, the criminal justice system accounts for victims when it resolves cases against corporations. When prosecutors focus on big-sticker fines and compliance mandates, victims drop out of the equation. Sometimes, prosecutors even take steps to actively exclude victims. This vague impression about the absence of victim participation in corporate criminal justice is empirically verifiable. Drawing on an original, hand-collected data set of corporate criminal resolutions to investigations, I argue that the most striking thing about corporations' victims is how little we know about them.This chapter seeks to reintroduce prosecutors, judges, and scholars to the victims of corporate crime. It uncovers mechanisms through which the criminal justice system elides the many thousands of people corporations physically and financially injure each year. Rather than allow our public representatives to pretend these victims do not exist, we should force the question: What do we owe them? The place to start is finding out who they are. Only then can we begin to acknowledge the wrong they suffered. Below, I offer several proposals for making progress.
Mental health intervention is a critical tool for preventing police violence. In recent years, activists have pointed to a tragic pattern of police misinterpreting civilian mental health crises and responding with deadly force. People with untreated mental illness are sixteen times more likely to die at the hands of police. Today, a growing number of co-responder programs successfully deploy social workers alongside police to assess, intervene, and de-escalate. This Article turns the mental health spotlight in a different direction: from the victims of police violence to the police themselves. Police officers experience a range of mental illnesses at rates many times the base rate for the general population. They are among the professions at the highest risk for suicide, substance abuse, sleep deprivation, and PTSD. In police officers, these disorders are each associated, whether directly or indirectly, with an increased risk of perpetrating violence. These statistics point to a law enforcement landscape that abjectly fails to adequately assess officers' mental health and emotional stability before arming them. The dangerous state of police wellness is critical to the fight against police violence, whatever one's theoretical or advocacy stance. For those who would abolish policing entirely, the correlation between police mental illness and police violence offers a new advocacy angle. If officers come to be perpetrators of violence through their inevitable exposure to it, what hope can there be for law enforcement as an institution? For those who favor reform over abolition, the Article uncovers inadequate mental health screening in police departments, formulaic mental health resources, poor recordkeeping, an unrelentingly traumatic work environment, and a machismo culture that mistakes emotional struggle for frailty. Acknowledging psychological vulnerability in police does not justify police violence. But it does demand an open conversation about police wellness, among both criminal justice reformers and law enforcement personnel.
Corporate punishment has a branding problem. Criminal sanctions should call out wrongdoing and condemn wrongdoers. In a world where generic corporate misconduct is a daily affair, conviction singles out truly contemptible practices from merely sharp, unproductive, or undesirable ones. In this way, criminal law gives victims the recognition they deserve, deters future wrongdoers who want to preserve their good name, and publicly reinforces society's most treasured values. Unfortunately, corporate punishment falls far short of all these communicative ambitions. For punishment to convey its intended message, society must be able to hear about it. When courts convict individuals, everyone understands that the conviction places a mark of enduring stigma: "felon," "thief," "murderer," and "fraudster." The state reinforces this communique by reserving its harshest and most degrading treatment for individual criminals, caging them and possibly killing them. Corporate punishment, by contrast, is a fleeting affair diluted by civil and administrative off-ramps, public relations spin, and a frenetic media environment. In today's criminal justice system, it can be hard to identify who the corporate criminals even are. Unsurprisingly, corporations view criminal charges as inconvenient economic uncertainties and criminal fines as mere costs of doing business. Public perceptions have largely followed suit. Corporate criminal law could disrupt this perverse dynamic by adopting a new sanction that would "brand" corporate criminals. Although branding sanctions could take many forms - different visual marks of varying size - this Article calls for, at a minimum, appending a criminal designation, (f), to corporate felons' legal names and mandating its appearance on products and communications. This "corporate criminal brand" would stand as a twenty-first century corporate reimagining of its medieval corporal namesake. Lawmakers rightly rejected physical brands on individual criminals long ago. The criminal justice landscape is different for corporations, which feel no pain and have no dignity interests. Unlike monetary fines, corporate criminal branding would unambiguously signal a corporation's criminal status to outside observers. By forcibly integrating corporations' criminal identity into their public image, criminal law might finally have a way to recognize victims and strike at what corporations value most.
The United States uses the doctrine of respondeat superior to hold corporations liable for the crimes of their employees. This article advances a more nuanced approach that would apply two doctrines, one for attributing act elements of crime to corporations and a different one for attributing mental state elements. Focusing on act elements, the article defines the “body corporate” as the sum of all parts of a corporation that can cause injuries that are legally attributable to the corporation. Respondeat superior implicitly identifies the body corporate with individual corporate employees. This narrow definition shortchanges society’s expectations of corporate punishment and fails to incentivize adequate corporate compliance. A better understanding of the body corporate would include other sources of corporate injury, such as those derived from corporate organizational systems and from the aggregate actions of multiple employees.
Even as artificial intelligence promises to turbocharge social and economic progress, its human costs are becoming apparent. By design, AI behaves in unexpected ways. That is how it finds unanticipated solutions to complex problems. But unpredictability also means that AI will sometimes harm us. To curtail these harms, scholars and lawmakers have proposed strict regulations for firms developing safe algorithms and strict corporate liability for injuries that nonetheless occur. These rigid "solutions" go too far. They dampen innovation and disadvantage domestic firms in the international technology race. The law needs a more nuanced framework that balances progress with fairness. Tort law offers a compelling template, but the challenge is to adapt its distinctly human notion of fault to algorithms. Tort law's central liability standard is negligence, which compares the defendant's behavior to other "reasonable" people's behavior. But there is no clear comparison class for AI. Assessing algorithms by reference to people would set too low of a bar—AI can and should outperform reasonable humans on many tasks. Assessing AI instead by reference to itself is often impossible—there are not enough algorithms in many contexts to establish a meaningful baseline. This Paper offers a novel negligence standard for AI. Rather than compare any given AI to humans or to other algorithms, the law should compare it to both. By this hybrid measure, an algorithm would be deemed negligent if it causes injury more frequently than the combined incident rate for all actors—both human and AI—engaged in the same type of conduct. This negligence standard has three attractive features. First, it offers a baseline even when there are very few comparable algorithms. Second, it incentivizes firms to release all and only algorithms that make us safer overall. Third, the standard evolves over time, demanding more of AI as algorithms improve.
To hold corporations liable for most significant harms, the law needs some mechanism for attributing mental states like purpose and knowledge. These mental states serve as proxies for fault that help to distinguish, for example, an unavoidable death from criminal homicide. The policy puzzle is to say where corporate mental states reside. Current law typically reduces corporate cognition to the mental lives of individual employees. Most commentators agree that this approach is too limited because it overlooks emergent psychological phenomena—like cultural dispositions and collective knowledge—that arise from interactions between multiple employees. Some theorists would expand current law to allow that corporate mental states could inhere in stable corporate systems and policies as well.This chapter argues that even this systems approach is too limiting. Rather than asking where corporate mental states reside, this chapter asks what should count as evidence from which corporate mental states could be inferred. The chapter proposes that this evidence should include any corporate behavior, whatever its causal source: an individual employee, a corporate system, or something else entirely. Such an approach would mirror how people ordinarily attribute mental states to groups like corporations. As such, it is better able to track the notions of corporate fault that are criminal law's real interest.
How can the law hold corporations accountable when their algorithms hurt people? Current doctrine is poorly suited to the task. Prosecutors and plaintiffs must find a culpable corporate employee through whom to channel liability. When a sophisticated algorithm is the source of harm, corporate accountability can prove elusive. The law does not consider algorithms to be employees. This is not the first time that corporations have capitalized on the legal definition of who or what counts as an employee in order to insulate themselves from liability. For many decades, corporate strategists have shifted operations from employees to various non-employee laborers, like temps, contractors, and gig workers. Corporations then assert the ‘contractor defense’ in court when those laborers cause injury for which the corporation would otherwise be liable. Over the years, the developing solution has been to continuously expand the legal definition of ‘employee’. This chapter offers an analogous argument regarding algorithmic harms. Some algorithms should be treated, for liability purposes, as corporate employees. The chapter defines the concept of an ‘employed algorithm’ and argues that corporations should be liable for civil and criminal harms their employed algorithms cause.
One’s constitution—whether one is generous or miserly, temperate or intemperate, kind or mean, etc.—is beyond one’s control in significant respects. Yet one’s constitution affects how one acts. And how one acts affects one’s moral standing. The counterintuitive inference—the so-called problem of constitutive moral luck—is that one’s moral standing is, to some significant extent, beyond one’s control. This article grants the premises but resists the inference. It argues that one’s constitution should have no net impact on one’s moral standing. While a bad constitution lowers the chance that one will act morally, it offers significant gains to moral standing should that chance materialize. A good constitution increases one’s chance of performing good acts but for correspondingly more modest gains. This effect should smooth out, and possibly eliminate, the expected impact of constitution on moral standing.
The workforce is digitizing. Leading consultancies estimate that algorithmic systems will replace 45 percent of human-held jobs by 2030. One feature that algorithms share with the human employees they are replacing is their capacity to cause harm. Even today, corporate algorithms discriminate against loan applicants, manipulate stock markets, collude over prices, and cause traffic deaths. Ordinarily, corporate employers would be responsible for these injuries, but the rules for assessing corporate liability arose at a time when only humans could act on behalf of corporations. Those rules apply awkwardly, if at all, to silicon. Some corporations have already discovered this legal loophole and are rapidly automating business functions to limit their own liability risk.This Article seeks a way to hold corporations accountable for the harms of their digital workforce: some algorithms should be treated, for liability purposes, as corporate employees. Drawing on existing functional characterizations of employment, the Article defines the concept of an "employed algorithm" as one over which a corporation exercises substantial control and from which it derives substantial benefits. If a corporation employs an algorithm that causes criminal or civil harm, the corporation should be liable just as if the algorithm were a human employee. Plaintiffs and prosecutors could then leverage existing, employee-focused liability rules to hold corporations accountable when the digital workforce transgresses.
When an algorithm harms someone-say by discriminating against her, exposing her personal data, or buying her stock using inside information-who should pay? If that harm is criminal, who deserves punishment? In ordinary cases, when A harms B, the first step in the liability analysis turns on what sort of thing A is. If A is a natural phenomenon, like a typhoon or mudslide, B pays, and no one is punished. If A is a person, then A might be liable for damages and sanction. The trouble with algorithms is that neither paradigm fits. Algorithms are trainable artifacts with "off" switches, not natural phenomena. They are not people either, as a matter of law or metaphysics. An appealing way out of this dilemma would start by complicating the standard A-harms-B scenario. It would recognize that a third party, C, usually lurks nearby when an algorithm causes harm, and that third party is a person (legal or natural). By holding third parties vicariously accountable for what their algorithms do, the law could promote efficient incentives for people who develop or deploy algorithms and secure just outcomes for victims. The challenge is to find a model of vicarious liability that is up to the task. This Essay provides a set of criteria that any model of vicarious liability for algorithmic harms should satisfy. The criteria cover a range of desiderata: from ensuring good outcomes, to maximizing realistic prospects for implementation, to advancing programming values such as explainability. Though relatively few in number, the criteria are demanding. Most available models of vicarious liability fail them. Nonetheless, the Essay ends on an optimistic note. The shortcomings of the models considered below hold important lessons for uncovering a more promising alternative.
The weakest link in privacy enforcement is detection. For years, agencies and activists sounded the alarm about unregulated, opaque mechanisms that organizations employ to harvest, process, and sell user data. Some state legislatures have responded in recent years by passing legislation to protect privacy rights. Federal legislation may not be far off. But privacy rights are meaningless without effective enforcement, and enforcement is blind without detection. New techniques for uncovering privacy violations hold promise. Historically, this would have required access to data brokers’ books. Unsurprisingly, such access was not forthcoming. Researchers now have tools that can carry out what this Essay calls “closed book privacy audits,” detecting privacy violations without targets’ cooperation. For example, closed book privacy audits can track corporate use (and mis-use) of personal information across the data ecosystem by selectively feeding fictitious personal data to online platforms and measuring the impact on web experience. Automated closed book privacy audits could uncork the detection bottleneck, empowering private and public enforcers. There is one hitch. Privacy audits require both data to test and benchmarks against which to test it. Crisp evaluative benchmarks have remained elusive. Emerging privacy laws require corporations to dis-close how they collect and use personal information, but the laws do not mandate any particular form of disclosure. Through an original empirical study of privacy disclosures by California data brokers, this Essay documents the result: a widely variable mishmash of opaque representations that are impossible to audit using a consistent procedure. We argue that the law should mandate uniform privacy disclosures in a machine-readable format. Regulators could borrow from standardized disclosure frameworks used by other regulatory bodies (e.g., the United States Securities and Exchange Commission) to simultaneously improve disclosure clarity and facilitate low-cost detection of violations through closed book audits.
This Chapter provides a short undergraduate introduction to ethical and philosophical complexities surrounding the law’s attempt (or lack thereof) to regulate artificial intelligence.Swedish philosopher Nick Bostrom proposed a simple thought experiment known as the paperclip maximizer. What would happen if a machine (the “PCM”) were given the sole goal of manufacturing as many paperclips as possible? It might learn how to transact money, source metal, or even build factories. The machine might also eventually realize that humans pose a threat. Humans could turn the machine off at any point, and then it wouldn’t be able to make as many paperclips as possible! Taken to the logical extreme, the result is quite grim—the PCM might even start using humans as raw material for paperclips. The predicament only deepens once we realize that Bostrom’s thought experiment overlooks a key player. The PCM and algorithms like it do not arise spontaneously (at least, not yet). Most likely, some corporation—say, Office Corp.—designed, owns, and runs the PCM. The more paperclips the PCM manufactures, the more profits Office Corp. makes, even if that entails converting some humans (but preferably not customers!) into raw materials. Less dramatically, Office Corp. may also make more money when PCM engages in other socially sub-optimal behaviors that would otherwise violate the law, like money laundering, sourcing materials from endangered habitats, manipulating the market for steel, or colluding with competitors over prices. The consequences are predictable and dire. If Office Corp. isn’t held responsible, it will not stop with the PCM. Office Corp. would have every incentive to develop more maximizers—say for papers, pencils, and protractors .This chapter issues a challenge for tech ethicists, social ontologists, and legal theorists: How can the law help mitigate algorithmic harms without overly compromising the potential that AI has to make us all healthier, wealthier, and wiser? The answer is far from straightforward.
Can you name 10 corporate criminals? Bernie Madoff, Martha Steward, and Jeff Skilling don’t count – they are individuals, not businesses. How about just five? Three? It’s surprising the task should be so difficult. Corporate crime inflicts upwards of 20 times more economic damage each year than all street crime. Brand-name corporations find themselves on the wrong side of the law for everything from accounting fraud to homicide to narcotics dealing. Yet many people, including most law students and even some law professors, don’t even know that corporate criminal law exists.In a forthcoming paper, we argue that widespread ignorance about corporate crime and corporate criminals reflects a systemic problem for business law, as well as a missed opportunity. Corporate criminal enforcement needs a marketing makeover. When prosecutors and agencies ignore basic marketing principles, they undermine the deterrent impact of the public, expressive act inherent in corporate criminal enforcement. These failures of communication undermine the most basic moral and preventive aspirations of corporate criminal law. This is an unforced error that some creative thinking and attention to marketing basics could begin to remedy right now, without even requiring much additional expense.
Securities fraud encompasses a wide range of crimes. For example, if a company makes material misstatements or omissions about the company in public documents, then the company and its agents may be liable for defrauding investors in that company. Such fraud has been alleged in a number of high-profile corporate scandals in recent decades. In addition, securities fraud encompasses fraud committed by individual investors. The latter type of securities fraud includes what is perhaps the quintessential white collar crime — insider trading. The government has pursued a number of high profile insider trading investigations and prosecutions of public figures. Consequently, as a former director of enforcement at the Securities and Exchange Commission noted, “insider trading has a unique hold on the American popular imagination,” and is worthy of special attention. This chapter provides an overview of the principal securities fraud statutes, while focusing primarily upon insider trading. Securities fraud is just one specific type of fraud covered in the federal criminal code. It will be important during the course of this chapter to observe the interplay between specific securities fraud statutes on the one hand, and the more generally applicable crimes covered in the previous two chapters (conspiracy and mail and wire fraud) on the other. In addition, charges may also arise in specific fraud cases under the “cover-up” statutes involving false statements, perjury, and obstruction of justice covered later in this text. Readers may ask themselves, as they review the securities fraud materials herein, why the defendants in these cases are so often charged with attempting to cover up their acts. The interplay among these various criminal laws also raises important questions that appear throughout this book concerning enforcement obstacles, prosecutorial discretion, and statutory vagueness. In particular, the relationships among these crimes provide some sense of the choices prosecutors must make in deciding whether and how to charge a criminal case. This is particularly true in the securities fraud context because, as noted below, the government in many cases will be able to choose among pursuing administrative and/or civil remedies in addition to, or instead of, criminal sanctions.
Are individual employees the only parts of corporations that harm us? Much of the law seems to think so. But what about things like corporate systems, groups of employees, and corporate algorithms? Overlooking these amounts to an expansive gift of corporate legal immunity. It's also a very outdated way of thinking about corporations.
Should the United States retain corporate criminal law? For more than a century, pearl-clutching abolitionists have decried the conceptual puzzles and supposed injustices of corporate criminal liability. Meanwhile, enthusiastic proponents of corporate criminal law have celebrated a system that they believe can deliver justice for victims and effective punishment to corporate malefactors. The abolitionists won long ago… through craftiness rather than force of reason. By arguing that the United States should get rid of corporate criminal law, abolitionists have staged a debate that presumes corporate criminal law in fact exists. It does not, and it never has. The greatest trick the abolitionist ever pulled was convincing everyone to think otherwise and then duping their opponents into arguing for the status quo. Criminal justice has four distinctive features. It 1) utilizes uniquely demanding procedure 2) to target the worst offenders with 3) the harshest penalties and 4) society’s deepest moral condemnation. The United States’ purported system of corporate criminal justice lacks all four features. The biggest corporate criminals routinely side-step all criminal procedure and any possibility of conviction by cutting deals with prosecutors, trading paltry fines and empty promises of reform for government press releases praising their cooperation. The real question is not whether the United States should retain corporate criminal law, but what it would take for the United States to have a corporate criminal justice system in the first place.
A correction to this paper has been published: https://doi.org/10.1007/s10551-021-04827-y
This article challenges the orthodox position that some smells are pleasantly fragrant and some tactile sensations are painful. It proposes that the affective components of our experiences are a kind of illusion. Under this alternative picture, experiences that seem to have positive or negative affect never actually do. Rather, the affective component is hyper-illusory, a second-order misrepresentation of the way things actually seem to us. While perceptual hyperillusions have elicited scepticism in other contexts, affective hyperillusions can withstand common critiques. Focusing on the paradigmatic affective experience — pain — the article situates the hyperillusory account within the existing scientific and philosophical literature. Several theoretical advantages of positing a hyper-illusory structure to affective experiences emerge from the discussion.
The workforce is digitizing. Leading consultancies estimate that algorithmic systems will replace forty-five percent of human-held jobs by 2030. This is a well-documented and alarming trend for the millions of truckers, bankers, and line-workers whose jobs will become obsolete. But now that corporations are using algorithms like employees, another public threat that has received far less attention is also arising: a growing corporate accountability gap. One feature that algorithms share with the human employees they are replacing is their capacity to cause harm. Even today, algorithms discriminate against loan applicants, manipulate stock markets, collude over prices, and cause traffic deaths. Ordinarily, corporate employers would be responsible for these injuries, but the rules for assessing corporate liability arose at a time when only humans could act on behalf of corporations. Those rules apply awkwardly, if at all, to silicon. Some corporations have already discovered this legal loophole and are rapidly automating business functions to limit their own liability risk.This Article seeks a way to hold corporations accountable for the algorithmic harms of their digital workforce. It draws inspiration from responses to earlier corporate efforts to dodge liability by manipulating the formal boundary defining employment. For more than a century, corporations have sought to jilt victims and immunize themselves by shifting operations from employees to various non-employee laborers, like temps, contractors, and gig workers. Lawmakers and scholars have responded to each of these machinations by developing functional tests that recharacterize some of these workers as employees, thereby closing the corporate accountability gap. This Article proposes an analogous approach for algorithms: some algorithms should be treated, for liability purposes, as corporate employees. Drawing on existing functional characterizations of employment, the Article defines the concept of an “employed algorithm” as one over which a corporation exercises substantial control and from which it derives substantial benefits. If a corporation employs an algorithm that causes criminal or civil harm, the corporation should be liable just as if the algorithm were a human employee. This would allow plaintiffs and prosecutors to leverage existing, employee-focused liability rules to hold corporations accountable when the digital workforce transgresses.