Economist Joshua Gans argues AI providers should bear liability for cyberattack losses
Joshua Gans, an economist at the University of Toronto, posted a thread on 09-22 introducing his new paper, which examines whether AI providers should bear liability for cybersecurity attacks suffered by their customers. His conclusion: from an economics standpoint, having providers share part of cybersecurity losses can be a welfare improvement. The issue had previously been raised by US Senator Josh Hawley and scholars including Gary Marcus.
Confirmed
- Gans's core model: attackers and defenders both use AI to hunt for vulnerabilities—one side to exploit them, the other to patch them—creating an ongoing cybersecurity game. Imposing liability on AI providers changes the game's structure, weakening defenders' incentives and thereby reducing attackers' attack intensity.
- He notes that what really drives expected losses is not the technology itself but AI providers' pricing: token prices affect both the attack/defense sides and productive users, while providers have no incentive to keep prices high.
- He argues that although under the traditional Section 230 internet logic platforms shouldn't be liable for user behavior, token prices shape the allocation between "productive use" and "security-attack use," so making providers internalize security losses corrects underpricing incentives and improves social welfare.
- He also points out a contrast: a monopolist would voluntarily keep prices high, but AI providers in a fiercely competitive market would not, so a liability scheme is harder to implement in competitive markets.
Why it matters
- AI models are used by both attackers and defenders, so how security liability is assigned directly shapes provider pricing and attack costs—an emerging economic perspective in AI regulation debates.
2026-09-22 ~ 2026-09-22 · 5 related posts
Primary sources
- [source] New Joshua Gans paper makes the economic case for AI provider cybersecurity liability — joshgans · 2026-09-22
- How AI liability reshapes the attacker-defender game, per Joshua Gans — joshgans · 2026-09-22
- AI provider liability hinges on pricing, not tech, argues economist Joshua Gans — joshgans · 2026-09-22
- [source] Liability for AI providers is welfare-improving but harder in competitive markets, says Gans — joshgans · 2026-09-22
- Economist Josh Gans: Making AI providers partly liable for cybersecurity losses is welfare-improving — joshgans · 2026-09-22