top of page

When AI Makes the Decision: The Responsibility Gap and the Risk of an Algorithmic Shield

לפני 6 ימים
זמן קריאה 14 דקות

Why artificial intelligence should not become a mechanism for distancing people and corporations from legal responsibility

Ronen Moshe, Adv.

August 2026

When AI Makes the Decision: The Responsibility Gap and the Risk of an Algorithmic Shield

As AI systems assume a larger role in commercial and professional decision-making, the legal problem is not only how to allocate responsibility when a system fails. A second risk is emerging: AI may become a convenient layer between the person who benefits from a decision and the person harmed by it. This article argues that the law should prevent that layer from becoming an algorithmic shield.


The sentence we are going to hear: “the system made the decision”

I suspect that lawyers, judges and regulators will hear one sentence with increasing frequency in the coming years: “the AI made the decision.” At first glance, that sounds like a technical explanation. In time, however, it may also become a legal defence.

A bank may say that a model classified a customer as high risk. An insurer may say that an automated tool recommended rejecting a claim. An employer may explain that recruitment software filtered out a candidate. A professional may rely on an AI-generated analysis that later proves seriously wrong. Management may say that no individual employee actually made the disputed decision.

Each statement may be factually accurate. The harder question is whether any of them should reduce legal responsibility.

Modern AI makes that question genuinely difficult. Machine-learning systems may be adaptive, probabilistic and opaque; the output may depend on training data, model architecture, system instructions, user input and later updates. Israeli policy documents have expressly identified lack of transparency, human oversight and accountability as regulatory challenges associated with AI, and earlier policy work described the practical difficulty of reconstructing the decision rules of some machine-learning systems.[1]

But I believe there is a second problem that deserves at least as much attention. The existence of a responsibility gap creates an incentive to use that gap. The law therefore has to ask not only who should be liable when an AI system causes harm, but also whether the technology is being allowed to become a screen behind which human and corporate responsibility can disappear.

I use the expression “algorithmic shield” here as a descriptive term, not as an existing legal doctrine. It describes an organizational structure in which responsibility is delegated to a system, fragmented among several actors, and then invoked after the event as a reason why no single actor should be held accountable.


Delegation should not become abdication

Organizations delegate decisions constantly. Boards delegate to managers. Managers delegate to employees. Companies outsource functions to contractors and rely on software, experts and external service providers. The law has never generally treated delegation as an automatic escape from responsibility. AI should not become the exception simply because the delegate is a machine rather than a person.

Consider a company that automates a decision process because the system is faster, cheaper and can operate at a scale that would otherwise require a much larger workforce. The company selects the use case, determines how much authority to give the system and receives the economic benefit. If the same company can later say that it is less responsible because no human being personally made the harmful decision, the legal structure becomes asymmetric: the organization keeps the benefit of automation while attempting to externalize the risk.

The greater the authority delegated to an autonomous system, the stronger the obligation should be to govern, monitor and document that delegation.

This does not mean that the deploying organization should always bear all liability. A defective model, negligent integration, misleading vendor representations or a failure in a third-party component may properly shift part of the responsibility elsewhere. My point is narrower: the autonomous operation of a system should not, by itself, be treated as a legal vacuum.

The direction of current regulation is already consistent with that idea. The EU AI Act requires defined high-risk systems to support logging and meaningful human oversight, and requires oversight arrangements that allow natural persons to understand system limitations, remain alert to automation bias, interpret outputs and, where appropriate, disregard, reverse or intervene in a system’s operation.  NIST’s AI Risk Management Framework similarly calls for clear organizational roles, accountability structures and executive responsibility for decisions concerning AI risk.[2][3]


The algorithmic shield can be accidental — or deliberately useful

The easiest case is accidental fragmentation. A model is developed by one company, integrated by another, deployed by a customer and used by an employee. When something goes wrong, every participant can point to someone else in the chain.

The harder case is where the structure itself becomes useful because it makes responsibility difficult to identify. Imagine a business in which management approves an AI decision process, the vendor refuses to disclose how the model works, employees are instructed to follow the recommendation in ordinary cases, logs are retained only briefly, and the contract allocates broad liability to the customer while giving the customer little access to the evidence needed to investigate a failure. None of those features necessarily proves wrongdoing. Together, however, they can create a very effective liability screen.

The same risk exists at the individual level. A manager may prefer to say that an algorithm selected the employee for dismissal. A professional may be tempted to characterize a harmful recommendation as the system’s conclusion rather than his own. An employee may “approve” an AI output without meaningful review, while the organization later points to that approval as proof that a human was responsible.

This is why I would be cautious about allowing causation doctrine to treat AI as though it were an independent external force. Where the harm belongs to the very class of decisions that an organization deliberately delegated to the system, the fact that the exact internal path of the model was not foreseeable should not automatically break the chain of responsibility.

AI may create not only a responsibility gap, but an incentive to manufacture one.


A practical test: control, benefit, prevention and evidence

Rather than asking only “who wrote the code?”, I think courts and businesses should approach responsibility through four practical questions.

First: who controlled the delegation? Who selected the system, chose the purpose for which it would be used and determined whether the AI would merely advise or effectively decide?

Second: who received the benefit? Economic benefit should not determine liability by itself, but it matters when one party captures the cost savings and efficiency of automation while another bears the consequences of failure.

Third: who was best positioned to prevent the harm? Could the provider have designed a safeguard? Could the deploying organization have required review, limited authority, tested the system more carefully or responded to earlier warnings?

Fourth: who controlled the evidence? If the injured person sees only the final result while the defendant or vendor controls the model version, configuration, input, logs and review history, that information asymmetry should matter.

Liability in autonomous systems should increasingly follow control, benefit, capacity to prevent harm and control over relevant evidence — not merely authorship of the underlying code.

I do not suggest that these four factors replace existing doctrines of duty, breach, causation or product liability. They are a practical way of asking where those doctrines should look when the human act is no longer a single visible decision.


The black box is also an evidence problem

From a litigation perspective, the “black box” is not primarily a philosophical problem. It is an evidence problem.

A claimant may know what decision was made, when it was made and what harm followed. But the claimant may not know which model version was operating; what material input was supplied; what system instructions existed; whether a human reviewed the result; whether earlier similar failures had occurred; or whether the system had changed between deployment and the event in dispute.

That is why logging and preservation rules may become central to AI litigation. The EU AI Act already requires high-risk AI systems to technically allow automatic recording of events over their lifetime, with logging capabilities designed to support traceability.  NIST’s Generative AI Profile likewise recommends inventories, documentation, incident review, provenance practices and retention mechanisms as part of AI risk management.[4][5]

For consequential decisions, I would expect the future litigation file to include an “AI black box”: the identity and version of the system, relevant inputs and outputs, material configuration or instructions, timestamps, human review, overrides and subsequent system changes. In many disputes, those records may become what emails, internal memoranda and minutes are in conventional commercial litigation: the material from which responsibility is reconstructed.


Israeli tort law: the evidence question may matter more than the label

Israeli tort law already contains tools that can engage with parts of this problem. Sections 35 and 36 of the Torts Ordinance provide the general negligence framework, and section 41 can shift the evidentiary burden in defined circumstances where the claimant did not know the circumstances that caused the harm, the relevant property was under the defendant’s full control and the circumstances are more consistent with negligence than with reasonable care.[6]

AI complicates the idea of “full control.” A company may control the decision to deploy the system and the authority given to it, while a vendor controls the model and technical logs. That may make section 41 useful in some cases and difficult in others. I would not assume that the doctrine automatically solves the AI problem.

A second Israeli doctrine may prove equally important: evidentiary damage. Israeli case law recognizes that where a defendant’s negligence deprives the claimant of evidence capable of proving a concrete disputed issue, the evidentiary burden may in appropriate circumstances shift with respect to that issue. The doctrine developed prominently in medical-record cases, but the Supreme Court has made clear that the principle is not limited to missing medical records.[7]

That becomes highly relevant to AI. If an organization knows that an automated system is making consequential decisions but fails to preserve the logs needed to reconstruct them, the legal question should not always be framed as the claimant’s inability to prove how the algorithm failed. In an appropriate case, the failure to preserve the evidence may itself have evidentiary consequences.

This is where the algorithmic shield and evidence law meet. A defendant should not be permitted to rely on opacity that it could reasonably have reduced through documentation, logging or preservation.


Human in the loop — or human as a liability device?

One of the most common responses to AI-risk concerns is that “there is always a human in the loop.” The phrase sounds reassuring. Sometimes it may mean very little.

Suppose an employee receives hundreds of AI recommendations each day. The employee does not understand how they were produced, has little time to investigate them, knows that management regards the system as more accurate than individual judgment and is evaluated partly on processing speed. Technically, the employee can reject a recommendation. In practice, almost nobody does.

Was there meaningful human supervision, or was the employee simply inserted into the process so that the organization could later say a human approved the decision?

The EU AI Act addresses this problem directly through its treatment of automation bias and meaningful oversight.  In my view, human oversight should carry legal weight only where the human has sufficient information, competence, time and authority to disagree with the machine. A rubber stamp should not become another layer of the algorithmic shield.[8]


Israel has already taken an important position in the financial sector

An important Israeli policy development points in the same direction. In December 2025, the inter-ministerial team examining AI use in the financial sector published its final report. Among its recommendations, the team stated that there was no reason to depart from the existing regulatory principle that legal responsibility remains with the regulated financial entity even when AI systems are used. It also recommended, as a general rule, prohibiting limitations of responsibility toward the customer for the operation of the AI system.[9]

That is not a general rule of Israeli tort law, and the report addresses the regulated financial sector. But the underlying principle is significant: the decision to use AI should not create a new legal actor between the regulated business and the customer affected by its conduct.

A bank remains a bank. An insurer remains an insurer. An employer remains an employer. A professional remains responsible for professional conduct. AI may change how these actors perform their functions; it should not automatically change who answers for those functions.


Product liability is beginning to adapt to software that continues to change

Traditional product-liability rules also reveal the difficulty. Israel’s Defective Products Liability Law imposes strict liability on a manufacturer for bodily injury caused by a defective product and defines defectiveness by reference to safety and warnings.  The statute was drafted for a world in which a product could usually be identified, released and then examined as a relatively stable object.[10]

AI systems do not always fit that model. Software can be updated after deployment. A model can change through provider updates, configuration, new data or integration with other services. Many AI-related harms will also be economic, discriminatory or informational rather than bodily injury, placing them outside the core structure of Israel’s strict product-liability statute.

The European Union has moved more explicitly toward the digital reality. Directive (EU) 2024/2853 treats software, including AI systems, as products for product-liability purposes and recognizes that a manufacturer may continue to exercise control through software updates, upgrades and related services. Member States must transpose the Directive by 9 December 2026; the previous directive continues to apply to products placed on the market or put into service before that date.[11]

The principle is important even beyond the Directive itself: in a digital product, release does not necessarily end control. Where control continues, the law has a stronger reason to ask whether responsibility continues with it.


Healthcare shows why formal human responsibility matters

Healthcare provides a particularly clear example of the distinction between using AI and transferring responsibility to AI. California Insurance Code section 10123.135 regulates the use of AI, algorithms and software tools in utilization review and management. It requires, among other things, that such tools not supplant healthcare-provider decision-making, and it provides that medical-necessity determinations denying, delaying or modifying services must be made by an appropriately licensed professional.[12]

The regulatory choice is worth noting. The law does not prohibit AI from assisting the process. It prevents the use of AI from dissolving professional responsibility for the decision itself.


The American platform cases offer a narrower warning

American platform law provides a different and more limited illustration of how technological intermediation can affect responsibility. Section 230(c)(1) of the Communications Decency Act provides that a provider or user of an interactive computer service shall not be treated as the publisher or speaker of information provided by another information content provider. In Force v. Facebook, the Second Circuit treated algorithmic matching and recommendation of third-party content as part of Facebook’s publishing functions for purposes of the claims before it.[13]

The Supreme Court later granted review in Gonzalez v. Google on questions involving targeted recommendations but ultimately disposed of the case without resolving the broader section 230 issue.  These cases concern a specific U.S. statutory immunity and should not be confused with general AI tort liability. Their relevance here is narrower: once technology becomes an intermediary between conduct and harm, legal characterization of that intermediary can have enormous consequences for responsibility.[14]

The next generation of AI law should therefore be careful not to create, intentionally or by accident, a general principle that algorithmic intermediation itself dilutes responsibility.


Contracts will often decide who ultimately pays

Public law determines whether an injured person has a claim. Contracts often determine who ultimately pays for it. That makes AI procurement agreements far more important than they may appear when the technology is first purchased.

The question should not be limited to “what can the system do?” A serious procurement process should also ask: “what happens when it does the wrong thing?”

From a practical contractual perspective, I would want material AI agreements to address, where relevant:

•  responsibility for training data, customer data and system inputs;

•  permitted uses and prohibited decision contexts;

•  known limitations, error rates and hallucination risks;

•  model changes, updates and notification duties;

•  human-oversight requirements and escalation procedures;

•  logging, retention and preservation of evidence;

•  security, privacy and intellectual-property incidents;

•  audit and investigation rights;

•  insurance, indemnification and appropriate liability caps; and

•  the allocation of responsibility when the vendor controls the technology but the customer faces the claimant.

One contractual structure deserves particular caution: the supplier controls the model, the updates and the relevant evidence, while the customer assumes virtually all liability for outputs. That is not merely a commercial allocation of risk. In a dispute, it can become a form of responsibility fragmentation.


A governance checklist before litigation begins

The practical lesson is not that businesses should avoid AI. In many settings that would be unrealistic and economically irrational. The lesson is that deployment should be accompanied by a visible responsibility architecture.

Before a consequential AI system is put into use, management should be able to answer at least these questions:

•  What decision is actually being delegated?

•  Who remains legally and organizationally responsible for the decision?

•  What may the system do without human approval?

•  Who can override it, and do they realistically have the information and authority to do so?

•  What evidence is preserved so that a disputed decision can later be reconstructed?

•  Who is responsible when the vendor changes the model or its behavior?

•  What happens operationally and contractually after a serious failure?

If an organization cannot answer those questions before deployment, it will have great difficulty answering them after a claim has been filed.


Conclusion: the algorithm is not a defendant

AI creates a genuine legal challenge because the relationship between intention, action and outcome is becoming less direct. But the solution cannot be to allow responsibility to evaporate together with that causal simplicity.

The law has spent centuries allocating responsibility among people, corporations, principals, agents, manufacturers and professionals. AI requires those rules to evolve. It should not provide an escape from them.

My concern is therefore broader than the technical black box. It is the possibility of a legal black box: a structure in which a decision travels through enough models, vendors, contracts and nominal human approvals that everyone involved can plausibly claim that someone — or something — else was responsible.

There will be cases in which responsibility properly lies with the developer, others in which it lies with the deploying organization, and many in which it should be distributed among several actors. The allocation will depend on the facts and the governing law.

A person or corporation should not be able to delegate a decision to AI, retain the benefits of that delegation, and then use the autonomy or opacity of the system as a screen against responsibility when the decision causes harm.

The algorithm may make the decision. The law must still be able to identify who was responsible for allowing it to do so — and who was responsible for preserving the evidence needed to prove it.

Author’s note: This article presents the author’s analysis and is intended for general discussion. It does not constitute legal advice.


[1] Ministry of Innovation, Science and Technology & Ministry of Justice, Responsible Innovation: Israel's Policy on Artificial Intelligence Regulation and Ethics (Dec. 2023) (identifying transparency, human oversight and accountability among core AI regulatory challenges); see also Ministry of Justice & Ministry of Innovation, Science and Technology, Policy on Artificial Intelligence Regulation and Ethics in Israel (2022 consultation paper) (discussing the difficulty, in some machine-learning systems, of reconstructing or tracing decision rules and the 'black box' phenomenon).

[2] Regulation (EU) 2024/1689 (Artificial Intelligence Act), arts. 14 and 26, OJ L 2024/1689, 12 July 2024 (human oversight and deployer obligations, including measures addressing automation bias and the ability to interpret, disregard, override or reverse outputs in relevant high-risk systems).

[3] National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (2023), GOVERN 2.1-2.3 (clear roles and responsibilities, training, and executive responsibility for AI risk decisions).

[4] Regulation (EU) 2024/1689 (Artificial Intelligence Act), art. 12 (requiring high-risk AI systems to technically allow automatic recording of events over the lifetime of the system to support appropriate traceability).

[5] National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1 (2024) (risk-management recommendations concerning documentation, inventories, provenance, incident review and human oversight).

[6] Torts Ordinance [New Version] (Israel), ss. 35-36 (negligence and foreseeability) and s. 41 ('the thing speaks for itself').

[7] See, e.g., CA 8151/98 Sternberg v. Chechik, PD 56(1) 539 (2001); CA 9328/02 Meir v. Laor, PD 58(5) 54, 64 (2004); CA 8693/08 Herman v. Sternberg (24 Mar. 2011) (Israeli evidentiary-damage doctrine and, in appropriate circumstances, burden shifting concerning a concrete factual issue where negligent loss or absence of evidence impairs proof).

[8] Regulation (EU) 2024/1689 (Artificial Intelligence Act), art. 14 (human oversight, including awareness of automation bias and the ability, where appropriate, to interpret, disregard, override or reverse outputs of high-risk AI systems).

[9] Bank of Israel, Final Report of the Inter-Ministerial Team Examining Uses of Artificial Intelligence in the Financial Sector, press release and final-report summary, 24 Dec. 2025 (recommending that legal responsibility remain with the regulated financial entity when AI is used and, as a general rule, that liability toward the customer not be limited because of the AI system's operation).

[10] Defective Products Liability Law, 5740-1980 (Israel), ss. 1-4 (definitions, manufacturer liability for bodily injury caused by a defective product, defectiveness and statutory defenses).

[11] Directive (EU) 2024/2853 on liability for defective products, recitals 13, 18-19 and arts. 21-22, OJ L 2024/2853, 18 Nov. 2024 (software, including AI systems, treated as products; continuing manufacturer control may include software updates and upgrades; Member States to transpose by 9 Dec. 2026, with the prior directive continuing to govern products placed on the market or put into service before that date).

[12] California Insurance Code § 10123.135(j) (as amended by SB 1120, effective 1 Jan. 2025) (AI, algorithms or other software tools used for utilization review may not supplant healthcare-provider decision-making, and medical-necessity determinations denying, delaying or modifying services must be made by an appropriately licensed professional).

[13] 47 U.S.C. § 230(c)(1); Force v. Facebook, Inc., 934 F.3d 53, 65-70 (2d Cir. 2019) (addressing Section 230 protection in relation to algorithmic matching and recommendations of third-party content in the claims before the court).

[14] Gonzalez v. Google LLC, 598 U.S. 617 (2023) (per curiam) (vacating and remanding without resolving the broader Section 230 issue concerning targeted recommendations).

 
 
bottom of page