When AI Causes Harm: The Slow Arrival of Consequences
For much of the past decade, the risk of building or deploying a harmful AI system was largely reputational. That is changing. A final family of approaches turns AI governance from guidance into consequence - attaching penalties to prohibited conduct and repurposing older laws to reach new harms. This article examines the adapting existing laws and liability approaches, the most demanding end of the regulatory spectrum.
Introduction
Not every response to AI harm requires a new statute. Some of the most effective moves extend laws that already exist. The adapting existing laws approach makes incremental amendments to sector-specific rules - in health, finance, justice or elections - and to cross-cutting ones such as criminal codes and data-protection law. Its advantage, the report notes, is that legislators can improve the framework gradually, learning as they go rather than legislating comprehensively in the dark (UNESCO, 2026).
Reaching New Harms with Old Laws
Two examples show the range. Article 22 of the European Union's General Data Protection Regulation gives a person the right not to be subject to a decision based solely on automated processing where that decision produces legal or similarly significant effects - a data-protection rule that reaches directly into automated AI decision-making (UNESCO, 2026). At the other end of the severity scale, Colombia's Law 2502 of 2025 amended the national Criminal Code to increase the penalties for impersonation when it is carried out through AI systems such as deepfakes (UNESCO, 2026). In both cases, an existing legal category - data rights, criminal impersonation - was stretched to cover a novel technological method.
Liability: Attaching a Price to Getting It Wrong
The liability approach goes further, assigning responsibility and sanctions for problematic uses of AI and backing mandatory standards of conduct with criminal, administrative or civil consequences (UNESCO, 2026). The clearest illustration is the penalty regime of the European Union's AI Act. Under Article 99, breaching one of the Act's prohibitions on banned AI practices can attract an administrative fine of up to 35 million euros or 7 percent of a company's total worldwide annual turnover, whichever is higher. Failing to meet other obligations - those placed on providers, importers, distributors and deployers - can draw fines of up to 15 million euros or 3 percent of global annual turnover, again whichever is higher (UNESCO, 2026). The turnover-linked ceilings are the point: for a large firm, the percentage is designed to exceed the flat sum, so that the cost of non-compliance scales with the capacity to cause harm.
The Psychology of Accountability
Consequences matter partly because automation blurs responsibility. Classic work by John Darley and Bibb Latané on the diffusion of responsibility showed that when accountability is shared or unclear, individuals become markedly less likely to act, each assuming the obligation belongs to someone else (Darley & Latané, 1968). Automated decision-making creates an unusually potent version of this effect: when an outcome can be attributed to the system, no single person feels answerable for it. The report identifies exactly this hazard among its cross-cutting concerns - a lack of accountability in the use of automated decision systems, alongside harms such as AI-enabled gender-based violence through deepfakes and the spread of election misinformation (UNESCO, 2026).
Liability rules work by re-attaching responsibility to a specific, identifiable party, and by making the expected cost of harm concrete enough to shape behaviour before harm occurs. This is the same deterrent logic that underlies much of the criminal and civil law: consequences that are certain and proportionate change the calculations of those who might otherwise externalise risk onto others.
Across this series, the nine approaches have moved from gentle guidance to binding sanction. It is fitting that the spectrum ends here. A society can encourage responsible AI with principles, cultivate it with sandboxes and illuminate it with transparency - but where those measures fail, the willingness to impose real consequences is what finally signals that the harm was never acceptable in the first place.
- Darley, J. M., & Latané, B. (1968). Bystander intervention in emergencies: Diffusion of responsibility. Journal of Personality and Social Psychology, 8(4, Pt. 1), 377-383.
- European Union. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation). eur-lex.europa.eu/eli/reg/2016/679/oj
- European Union. (2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 99. eur-lex.europa.eu/eli/reg/2024/1689/oj
- República de Colombia. (2025). Ley 2502 de 2025 (modificación del Código Penal).
- UNESCO. (2026). Governing AI: Nine emerging approaches for lawmakers worldwide. United Nations Educational, Scientific and Cultural Organization.
This article was drafted with the research assistance of AI (Claude) and edited under human editorial oversight. Its factual claims are drawn from UNESCO's 2026 policy brief and the public legal instruments it cites. Full sourcing practice for this site follows the standing Corrections & Sources approach - the author's own research process lives at vivekamohandas.com →