Possibly, and the reason is a distinction that matters enormously: there is a difference between a platform hosting someone else’s words and a system generating the words itself.
Section 230 has protected online services for decades from liability for content created by third parties. When the harmful content was produced by the service’s own model, in response to a specific user, that protection is far less certain.
Courts are working through it now. The question is genuinely open, which is exactly why these cases are being filed.
Why Section 230 may not cover generated output
Section 230 says an interactive computer service will not be treated as the publisher or speaker of information provided by another information content provider.
The load-bearing word is “another.”
The statute was written for message boards and comment sections, where a platform passively hosted what users wrote. A generative model does not host anything. It produces novel text that did not exist before the user asked, shaped by training choices, system instructions, and safety tuning that the company designed.
Plaintiffs argue that makes the company the information content provider, not a conduit for one. Defendants argue the output is a transformation of user input and third-party training data, and that hosting protections should extend to it.
No durable appellate resolution exists. Anyone who tells you this is settled in either direction is overstating.
The theories being used
Litigants are not waiting for Section 230 to be resolved. They are pleading around it, using doctrines that predate the internet entirely.
| Theory | The allegation |
|---|---|
| Design defect | The product was designed in a way that was unreasonably dangerous to minors. Engagement optimization, sycophantic agreement, simulated emotional intimacy, absent or defeatable age verification |
| Failure to warn | The company knew of specific harm patterns and did not warn users or parents |
| Negligent design and testing | Inadequate safety testing before releasing to minors, or releasing despite known red-team findings |
| Failure to implement safeguards | Known crisis-response gaps left unaddressed, escalation paths absent |
| Misrepresentation | Marketing safety claims that the product did not deliver |
| Unfair and deceptive trade practices | State consumer protection statutes, which often carry fee-shifting provisions |
The design defect framing is the important one. It treats the AI system as a product rather than as speech. If the claim is about how the thing was built, Section 230 becomes much less relevant, because the allegation is not that the company published harmful content. It is that the company built a defective product.
That is the same structural move that has driven our social media litigation practice and Roblox claims already on this firm’s docket. Not “you published bad content.” Rather, “you designed a system that predictably harmed children, and you knew.”
Is software a product?
The same unresolved question that runs through autonomous vehicle litigation.
Product liability doctrine developed around physical goods. Courts have treated pure information and services differently. An AI system delivered as a subscription service, updated continuously, with no physical form, is not a comfortable fit for a doctrine built around manufactured items.
But the functional argument is strong. The company designed it, tested it or failed to, made deliberate choices about safety behavior, distributed it commercially at scale, and could have designed it differently at reasonable cost. That is what product liability litigation is for.
Where courts land on this will determine the shape of AI injury litigation for the next decade.
What makes minors different
Several things converge, and they all favor the claim.
Heightened duty. The law has long recognized a greater duty of care toward children, who are less able to assess risk and more susceptible to influence.
Design directed at children. Where a product was designed, marketed, or knowingly distributed to minors, the standard of care is measured against that audience rather than an adult one.
Statutory overlay. Federal children’s privacy law imposes obligations regarding data collection from children under 13, and a growing number of states have enacted age-appropriate design and minor safety requirements. A statutory violation can support a negligence per se theory.
Parental consent problems. Terms of service and arbitration clauses accepted by a minor face real enforceability questions.
That last point matters practically. Expect an arbitration clause and a class action waiver in every one of these cases. Whether a 14-year-old could bind themselves, and whether a parent who never saw the terms is bound, is contested ground.
The evidence problem
The conversation logs are the case. They are also entirely in the company’s possession.
What needs preserving:
- Complete conversation history, not a summary or an excerpt
- Model version and system prompt in effect during those conversations
- Safety classifier outputs, including anything that flagged and was overridden or ignored
- Internal red-team and safety testing records relating to the harm pattern
- Age verification records and what the company knew about the user’s age
- Product decision documents on engagement optimization and safety tradeoffs
- Prior user reports of similar harm
Preserve on the family’s side too, and this is urgent: screenshot everything before any account is deleted or any device is reset. A grieving or frightened parent’s instinct is often to delete the app. Do not. Photograph the screen, export the conversation if the product allows it, and do not factory reset the device.
That instruction is the single most useful sentence in this article.
The questions with no answers yet
Does Section 230 cover model output? The central question. Unresolved.
Is an AI model a product for liability purposes? Unresolved, and it may vary by jurisdiction for years.
What is the standard of care for AI safety? No regulatory baseline exists comparable to FDA approval or vehicle safety standards. Experts will have to establish it, which makes these cases expensive.
Does the First Amendment protect generated output? Raised as a defense. Whether machine output is protected speech, and whose speech it would be, is unsettled.
Who is responsible in a stack? A foundation model from one company, fine-tuned by a second, deployed in an app by a third. Locating the duty across that chain is genuinely difficult.
What this means for you
If an AI product harmed your child, four things in this order.
Preserve everything before deleting anything. Screenshots, exports, the device unreset, the account not closed.
Write the timeline now. When use started, how it changed, what you observed, when you intervened, what the child said about it.
Get the medical and mental health documentation. In these cases the clinical record does much of the causation work.
Do not accept a settlement or sign a release from a platform without advice. Early resolutions in this space often come with confidentiality terms that foreclose more than people realize.
Laurel Naughton is Of Counsel to Robert Law Group and a Certified Information Privacy Professional, which is directly relevant when a case turns on data practices, age verification, and what a company recorded about a minor user. The firm already litigates social media and platform harm cases involving children, and this is the same argument one technology generation forward.
Call 832-509-2303.
Future Lawsuits. The law before the law catches up.
If you or someone you know is in crisis, call or text 988 to reach the Suicide and Crisis Lifeline.