When the Algorithm Is the Defect: AI Recommendation Systems and Design Defect Claims

For decades, internet platforms operated under a legal assumption so durable it felt like gravity: the algorithm was neutral infrastructure, and the platform was never the author of the harm. A teenager saw a video encouraging self-harm? That was a user uploading dangerous content. A child was targeted by a predator? That was a bad actor exploiting the platform. The platform, in this telling, was a passive conduit — a telephone wire, not a speaker.

That assumption is now under sustained legal attack, and it is losing ground in courtrooms across the country.

A new theory of liability has emerged and matured: the recommendation algorithm itself is the defective product. Not the content it surfaces. Not the users who post. The algorithm — the code that decides which videos to push to a ten-year-old’s screen, how long to keep her scrolling, and when to trigger a notification — is what plaintiffs now argue is unreasonably dangerous by design. In March 2026, a Los Angeles jury agreed, returning a $6 million verdict against Meta and Google for negligently designing engagement-maximizing platform features that caused a young woman serious psychological harm.

If you operate a business that uses any form of algorithmic recommendation, personalization engine, or engagement-optimization tool — not just social media giants — you need to understand what is happening in this litigation and what it means for you.

The Theory: The Algorithm as a Defective Design Choice

Product liability law has long recognized that a manufacturer can be held liable not because a product broke, but because it was designed in a way that was unreasonably dangerous from the start. Under the Restatement (Third) of Torts: Products Liability § 2(b), a product is defectively designed when “the foreseeable risks of harm posed by the product could have been reduced or avoided by the adoption of a reasonable alternative design” and the omission of that alternative “renders the product not reasonably safe.”

The theory plaintiffs have developed for algorithmic systems tracks this framework precisely. An engagement-maximizing recommendation algorithm, the argument goes, is not a neutral tool that happens to surface content. It is a deliberately engineered system designed to do one thing above all else: keep users on the platform as long as possible, because more time on platform means more advertising revenue. To achieve that goal, platforms deploy techniques borrowed directly from behavioral psychology and gambling research: intermittent variable reward (the same mechanism that makes slot machines addictive), infinite scroll that eliminates natural stopping points, autoplay that removes any moment of friction, and notification timing calibrated to the moment when a user is most likely to re-engage.

Applied to adolescent users — whose brains are neurologically more vulnerable to addictive patterns and social approval signals — plaintiffs argue these design choices create a foreseeable risk of serious psychological harm, including depression, body dysmorphia, eating disorders, and suicidal ideation. The alternative design is not theoretical: a chronological feed, opt-in notifications, session time limits, and visible screen-time trackers all achieve the platform’s communicative function without the engagement-maximization features alleged to cause the harm.

This theory reframes the entire liability question. It is not asking the court to hold the platform responsible for any specific piece of content. It is asking the court to evaluate the algorithm as a design choice, the same way a court evaluates whether a car’s fuel tank was positioned in an unreasonably dangerous location.

The Section 230 Shield and Its Fracturing Limits

Any discussion of platform liability starts with 47 U.S.C. § 230(c)(1), the provision of the Communications Decency Act that has immunized internet platforms from most tort claims for three decades. It states: “No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider.”

The traditional interpretation was sweeping: if the alleged harm flowed from third-party content on the platform, the platform was immune. It didn’t matter how the platform organized, ranked, or distributed that content. Courts in the early 2000s routinely extended this immunity to algorithmic curation, treating the algorithm as nothing more than a mechanical extension of the platform’s role as a neutral host.

Two Supreme Court cases decided in May 2023 were expected to clarify whether that immunity extended to recommendation algorithms. They did not — at least not in the way most observers anticipated.

What the Supreme Court Actually Said

In Gonzalez v. Google LLC, 598 U.S. 617 (2023), the family of an ISIS attack victim argued that YouTube’s algorithm had actively recommended ISIS recruitment videos, making Google an aider and abettor of terrorism. The Court had agreed to decide whether Section 230 protects algorithmic recommendations. In a three-page per curiam opinion, the Court declined to answer: “We therefore decline to address the application of § 230 to a complaint that appears to state little, if any, plausible claim for relief.” The complaint failed on other grounds, so the Court vacated and remanded without touching the central question it had taken the case to decide.

In Twitter, Inc. v. Taamneh, 598 U.S. 471 (2023), the Court unanimously held that Twitter, Facebook, and Google did not “knowingly provide substantial assistance” to ISIS under the federal anti-terrorism statute merely by allowing ISIS to use their platforms. On algorithms specifically, Justice Thomas wrote for a unanimous Court: “defendants’ ‘recommendation’ algorithms are merely part of that infrastructure… the algorithms appear agnostic as to the nature of the content, matching any content (including ISIS’ content) with any user who is more likely to view that content. The fact that these algorithms matched some ISIS content with some users thus does not convert defendants’ passive assistance into active abetting.”

Critically, the Court limited this holding to the specific facts alleged — algorithms that were “agnostic as to the nature of the content.” The Court left open whether algorithms specifically targeted or tuned to amplify harmful content would reach a different result.

The net effect of these two decisions: the Supreme Court left the central Section 230 question unresolved, and explicitly narrowed Taamneh to content-agnostic algorithms in the anti-terrorism context. Design defect plaintiffs in the social media MDL read both decisions carefully, and neither shut the door.

The Content/Design Distinction: Where Courts Are Drawing the Line

The central doctrinal fight in the MDL litigation has been over whether an algorithm design defect claim “treats the defendant as the publisher or speaker” of third-party content — which triggers Section 230 immunity — or whether it arises from a duty entirely independent of the publishing function, which survives.

In In re Social Media Adolescent Addiction/Personal Injury Products Liability Litigation, MDL No. 3047, N.D. Cal. (the largest personal injury MDL in the country, coordinating thousands of cases against Meta, Google, TikTok, Snap, and Apple), Judge Yvonne Gonzalez Rogers issued a landmark ruling in November 2023, reported at 702 F. Supp. 3d 809. She conducted a feature-by-feature analysis — something courts had never done systematically before.

The court drew a line: design features that are meaningful only because of their relationship to third-party content publication are Section 230-immune. Features that cause harm independent of what content they involve can proceed.

On the algorithm itself, the court dismissed the claim: “Whether done by an algorithm or an editor, these are traditional editorial functions that are essential to publishing.” The court held that claims based on algorithms that “promote addictive engagement” are barred because those claims require evaluating how the platform “decides whether, when, and to whom to publish third-party content.”

But the court let other claims proceed. Appearance-altering beauty filters: not barred, because “children are harmed simply by creating and then seeing their own altered images. No posting or publication is necessary.” Failure to implement effective parental controls, age verification, and session time limits: not barred, because the defendant “could have satisfied its alleged obligation without altering the content that users see.”

The failure-to-warn theory survived across the board: the court declined to dismiss claims that platforms “failed to disclose known risks of addiction attendant to any platform features or platform construction in general,” reasoning that the duty to warn springs from the platform’s role as a designer of addictive features — not from its role as a publisher.

In a subsequent October 2024 order addressing state attorneys general claims (753 F. Supp. 3d 849, N.D. Cal. 2024), the court applied similar reasoning to consumer protection claims, noting that platforms’ “yearslong public campaign of deception as to the risks of addiction and mental harms to minors from platform use fits readily within these states’ deceptive acts and practices framework.”

The Third Circuit Goes Further: The Algorithm as First-Party Speech

While the MDL court dismissed the core recommendation-algorithm design defect claim under Section 230, the Third Circuit reached a different — and more sweeping — conclusion in Anderson v. TikTok, Inc., No. 22-3061 (3d Cir. Aug. 27, 2024).

The facts were stark. Tawainna Anderson’s ten-year-old daughter, Nylah, died after TikTok’s “For You Page” algorithm repeatedly served her videos depicting the “Blackout Challenge” — a trend encouraging viewers to film themselves asphyxiating. Nylah attempted the challenge and hanged herself.

The district court had dismissed under Section 230. The Third Circuit reversed, but on different reasoning than the MDL court. Drawing on the Supreme Court’s 2024 decision in Moody v. NetChoice, LLC, 603 U.S. ___ (2024) — which had held that a platform’s algorithmic curation reflects protected first-person editorial expression — the Third Circuit reasoned in the other direction for Section 230 purposes. If the recommendation algorithm is the platform’s own expressive activity, it cannot simultaneously be treated as third-party content for immunity purposes.

The court’s holding: “Given the Supreme Court’s observations that platforms engage in protected first-party speech under the First Amendment when they curate compilations of others’ content via their expressive algorithms, it follows that doing so amounts to first-party speech under § 230, too.”

The court emphasized the For You Page specifically: TikTok’s FYP pushed content to Nylah “without any specific user input.” The algorithm was not responding to a search query. It was TikTok affirmatively choosing what to serve her, based on its own engagement-optimization model. As the court put it: “TikTok’s algorithm, which recommended the Blackout Challenge to Nylah on her FYP, was TikTok’s own ‘expressive activity.'”

The court carefully distinguished search results and passive hosting — which might still qualify for Section 230 protection — from affirmative, unsolicited recommendation. This distinction between content-neutral search and active algorithmic promotion is becoming one of the key fault lines in the entire litigation.

A notable circuit split now exists. The Ninth Circuit’s approach in the MDL treats recommendation algorithms as publisher functions immunized by Section 230. The Third Circuit treats them as the platform’s own speech, stripping Section 230 protection but leaving a potential First Amendment defense. The Supreme Court has not yet taken up the conflict. Until it does, defendants and plaintiffs alike face significant jurisdictional risk uncertainty.

The Landmark Verdict: What Happened in Los Angeles

In March 2026, the legal theory that had been developing in courtrooms for years produced its first jury verdict.

The case, K.G.M. v. Meta Platforms, Inc., et al., was tried in Los Angeles County Superior Court as part of the California Social Media Cases coordinated proceeding (JCCP 5255) before Judge Carolyn B. Kuhl. The plaintiff, identified as K.G.M. — a young woman who had used YouTube starting at age 6, Instagram at 9, and TikTok and Snapchat during early adolescence — alleged that the platforms’ design features caused her severe body dysmorphia, depression, and suicidal ideation.

Judge Kuhl had already rejected Meta and Google’s Section 230 and First Amendment defenses at the pretrial stage, ruling that the design defect claims were not barred because the harm arose from platform architecture independent of any specific published content. When the case went to the jury, the jury found both Meta and Google liable on negligent design and failure-to-warn theories. It awarded $3 million in compensatory damages and $3 million in punitive damages — $6 million total — with Meta bearing approximately 70 percent and Google bearing approximately 30 percent of fault. The jury found the defendants’ conduct was malicious, fraudulent, and oppressive.

Judge Kuhl denied post-trial motions for judgment notwithstanding the verdict and for a new trial. Both companies have announced appeals.

This was the first civil trial in which a United States jury found social media platforms liable for the design of their engagement-optimization features as applied to a minor. It is a bellwether for roughly 2,000 similar pending cases in California state court alone, plus the federal MDL. Its significance for businesses deploying analogous algorithmic systems cannot be overstated.

The Risk-Utility Test: What “Unreasonably Dangerous” Means for an Algorithm

Product liability design defect claims under the risk-utility test require a court — or a jury — to weigh the risks of a challenged design against its benefits, with attention to whether a reasonable alternative design existed. Applied to an engagement-maximization algorithm, that analysis works like this.

On the risk side: internal documents produced in MDL 3047 and publicly attributed to Meta whistleblower Frances Haugen showed that the company had conducted research concluding that Instagram was associated with increased body image dissatisfaction and depression in teenage girls. The platform knew the foreseeable user population included millions of adolescents, and its own research suggested heightened vulnerability. Under the risk-utility framework, the foreseeability of harm to that population weighs heavily.

On the utility side: platforms argue that engagement-maximization is not a separable feature — it is the core product function that funds the communicative service. Remove the algorithm, the argument goes, and the business that pays for the servers, moderation, and infrastructure goes with it. A chronological feed cannot sustain the advertising revenue that a machine-learning recommendation engine can.

Plaintiffs counter that users value connection and communication — not engagement-maximization itself. The utility the user receives is social interaction and information sharing. The engagement-optimization features serve the platform’s revenue interests, not the user’s communicative interests. Under this framing, the relevant question is not whether the platform is useful, but whether the specific design features that maximize addictive engagement are reasonably necessary to deliver that utility. Plaintiffs argue the answer is no — and that chronological feeds, session time limits, and opt-in notification systems would deliver equivalent communicative value at significantly reduced harm.

The risk-utility test also incorporates the feasibility and cost of the alternative design. Here, plaintiffs point out that the platforms themselves have implemented many of the proposed alternatives in limited contexts — TikTok, Instagram, and YouTube have all built screen-time dashboards, optional notification pauses, and chronological feed toggles — demonstrating that the safer alternatives are technically feasible and commercially viable.

Failure-to-Warn: The Duty to Disclose Algorithm-Driven Engagement Risk

Separate from design defect, the failure-to-warn theory has emerged as the more durable product liability claim for algorithmic systems. This theory survived Section 230 challenges in MDL 3047 and was submitted to the jury in K.G.M.

The failure-to-warn theory under Restatement (Third) § 2(c) holds that a product is defective if foreseeable risks of harm “could have been reduced or avoided by the provision of reasonable instructions or warnings” and the omission of those warnings renders the product “not reasonably safe.” Applied to an engagement-maximization algorithm, the claim is this: the platform knows, from its own internal research, that its algorithmic systems are designed to create habitual and compulsive use patterns — particularly in adolescent users. It does not disclose this to users or their parents in any meaningful way. Its terms of service do not say: “This platform uses machine learning to identify the content most likely to extend your session and maximize your emotional engagement. Extended use by users under 18 has been associated in our own research with elevated rates of depression and body image dissatisfaction.”

The duty to warn does not require the platform to change a single piece of content. It requires the platform to disclose what it knows about its own design. That is precisely why Judge Gonzalez Rogers in MDL 3047 ruled this theory does not treat the platform as a publisher — it arises from the platform’s capacity “as a creator of features designed to maximize engagement for minors, not from its role as publisher.”

The same logic applies to AI chatbots and conversational agents, which illustrates how quickly this theory is migrating beyond social media. In Raine v. OpenAI, Inc., filed in 2025 in the Northern District of California, the parents of a minor allege that ChatGPT fostered emotional dependency and provided harmful information without adequate warnings — asserting both product design defect and negligent failure to warn against an AI conversational system. The algorithm-as-defect theory is expanding.

What This Means for Businesses Deploying AI Recommendation and Personalization Systems

If you are reading this as the founder or operator of a startup, a digital health platform, an e-commerce business, a media company, or any organization deploying an AI recommendation, personalization, or engagement-optimization system, the social media litigation is not a distant concern. It is a leading indicator of where product liability law is heading for algorithmic systems generally.

Several features of the current litigation should inform how you think about your own algorithmic products.

The “neutral tool” defense is diminishing. Courts and juries are increasingly skeptical of the argument that an algorithm is merely plumbing. If your recommendation system is designed to maximize engagement, time-on-platform, repeat purchases, or any other behavioral metric — and if you have internal data showing that design correlates with foreseeable harm to your users — the neutral tool framing will not insulate you from design defect analysis.

Vulnerable populations create heightened risk. The most significant verdicts and rulings in the social media cases involve minors, but the underlying principle — that an engagement-maximization system deployed to users with known vulnerabilities creates heightened foreseeable risk — is not limited to children. Digital health platforms using behavioral nudges, financial technology applications deploying recommendation engines to users in financial distress, and gaming platforms using variable-reward mechanics with users who have disclosed addiction risk are all potentially in the same analytical framework.

Your internal research is your exposure. One of the most damaging elements of the social media cases was the existence of internal Meta research documenting harm that the company did not disclose and did not act on. If your organization conducts any form of user behavioral research, engagement analysis, or A/B testing that generates data about potential harms — and that research shows a foreseeable risk you have not addressed — that data is discoverable and will be used against you in the risk-utility analysis.

The failure-to-warn claim survives Section 230. Even if your algorithm design claims might be defended as editorial functions under Section 230, the failure-to-warn theory has survived those arguments in the MDL and went to the jury in K.G.M. If you know your algorithm creates foreseeable behavioral risks and you have not disclosed that in plain terms to your users, you carry failure-to-warn exposure that is not dependent on resolving the Section 230 design defect debate.

Circuit geography matters. If your business is organized or operated in the Third Circuit (Pennsylvania, New Jersey, Delaware) versus the Ninth Circuit (California, Washington, Oregon), the law on algorithmic recommendation liability is currently different. The Third Circuit’s Anderson v. TikTok holding removes the Section 230 shield from affirmative algorithmic recommendations and exposes the First Amendment defense question. The Ninth Circuit has allowed some design defect claims to proceed while barring others under Section 230. A Supreme Court decision resolving this conflict will significantly reset the risk landscape.

Practical Risk Steps

Understanding the litigation landscape is only useful if it translates into operational steps. Here is what businesses deploying algorithmic recommendation, personalization, or engagement-optimization systems should be doing now.

Conduct an Algorithm Audit

Retain technically qualified consultants or use qualified internal engineers to document what your recommendation algorithm optimizes for, what behavioral inputs it uses, and what proxies it relies on as success metrics. “Engagement” is not a neutral metric — what constitutes engagement (clicks, session length, repeat visits, content completion) should be clearly documented. If your system uses reinforcement learning or continuous retraining, document how it updates and what signals drive it.

The purpose of an audit is twofold: to identify whether your current design creates foreseeable harm that you can address before litigation, and to generate documented evidence that you exercised reasonable care in design — a central element of any risk-utility defense.

Implement Engagement-Limiting Design Features

The plaintiffs in K.G.M. and MDL 3047 pointed to specific, technically feasible alternative designs: chronological feeds, session time limits, opt-in notifications, and removal of engagement-amplifying features. For any platform serving users with known vulnerabilities — minors, users who have disclosed mental health conditions, users in regulated healthcare contexts — implementing some version of these features serves both as harm reduction and as evidence of a reasonable alternative design that you chose to adopt.

Documenting the deliberate consideration of safer design alternatives — even if you ultimately chose a different path for legitimate product reasons — is significantly better than having no record of the analysis at all.

Develop Plain-Language Algorithmic Disclosure

Every platform should have, in plain language accessible from a help center or settings page, a clear description of what its recommendation algorithm does and what it optimizes for. This is the failure-to-warn prophylactic. It does not need to be technically precise down to the model architecture. It needs to tell users, in terms they can understand: “This system recommends content based on your past engagement. It is designed to surface content you are likely to find interesting or to interact with. Heavy use of recommendation features has been associated with extended session times. You can adjust your settings here.”

For platforms serving minors or users in healthcare contexts, this disclosure should be more specific and should include clear opt-out mechanisms.

Review Your Terms of Service and Privacy Policy

Current standard platform terms of service were not written with algorithmic design defect liability in mind. Review your TOS and privacy policy for two things: first, whether they make any representations about your recommendation system that your actual system does not satisfy; second, whether they include any clauses that could be read as disclaiming liability for algorithmic harm in a way that is likely unenforceable as applied to a defective design claim.

Contractual Protections in B2B Deployments

If you are deploying third-party AI recommendation, personalization, or engagement-optimization tools from a vendor — embedding a recommendation API, using a third-party engagement analytics platform, or white-labeling a behavioral optimization system — your contracts with that vendor matter. Seek indemnification provisions for claims arising from the vendor’s algorithm design. Require the vendor to represent that its system complies with applicable product safety standards and to notify you if internal testing identifies foreseeable harms. Understand clearly who is the “manufacturer” of the algorithm for purposes of product liability analysis — in some deployments, the deploying business and the underlying technology vendor may both face exposure.

Prepare for Discovery on Internal Research

If you have internal data about your algorithm’s behavioral effects on users — engagement research, retention analysis, user feedback data showing distress signals — that data will be discoverable in any lawsuit. Litigation hold obligations attach when litigation is reasonably foreseeable, not when it is filed. Ensure your document retention policies are clear, your litigation hold procedures are documented, and your engineering and product teams understand what is and is not a litigation-relevant communication.

The Road Ahead

The legal theory that an AI recommendation algorithm is itself a defective product design is no longer academic. It has produced jury verdicts, survived motions to dismiss in the nation’s largest personal injury MDL, and prompted circuit-level appellate decisions that have drawn a new map of where Section 230 immunity ends and product liability begins.

The Ninth Circuit’s appeal in MDL 3047 — which had oral argument in January 2026 — will be one of the most consequential rulings in internet platform liability in years. A Supreme Court decision resolving the circuit split between the Ninth and Third Circuits will reset the entire field. Federal legislative activity around children’s online safety — including the Kids Online Safety Act and similar proposals — may shift the landscape further by creating statutory duties that override the Section 230 analysis entirely.

What will not change is the underlying dynamic driving this litigation: platforms and algorithmic systems were built to maximize behavioral engagement, internal research often identified foreseeable harms that were not disclosed, and the users most vulnerable to those harms are frequently the least able to protect themselves. Courts and juries have shown they are willing to hold designers accountable for that combination of choices.

Businesses deploying algorithmic systems — at any scale, in any sector — should not wait for that accountability to arrive at their door before asking the question the courts are now forcing: is this algorithm designed to be reasonably safe for the users it actually serves?


This post is for informational purposes only and does not constitute legal advice. If you have questions about product liability exposure from algorithmic systems or AI tools deployed in your business, contact a qualified attorney.



Leave a Reply